Review
CROMEDOME
CVE published 2026-07-20
CVE-2026-13577
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-20T08:16:28.987Z and has not been modified since then. The vulnerability affects Dancer2 versions through 2.1.0 for Perl, generating insecure session IDs when CSPRNG modules are unavailable. The fallback session ID is generated from low-entropy sources, including a SHA-1 hash of the built-in rand fu [truncated]