CVE-2026-8450: Http Daemon Pm Cwe 000 Cve 2026 8450

The 2-argument `open()` in Perl evaluates shell-magic characters (like `|`, `<`, and `>`), which can result in OS command injection or arbitrary file manipulation if the filename is attacker-controlled. Always use the 3-argument `open()` (e.g., `open(my $fh, '<', $file)`) to interpret the path explicitly.

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Generic
greprules fetch cve-2026-8450-http-daemon-pm-cwe-000-cve-2026-8450 --engine opengrep

Description

The 2-argument `open()` in Perl evaluates shell-magic characters (like `|`, `<`, and `>`), which can result in OS command injection or arbitrary file manipulation if the filename is attacker-controlled. Always use the 3-argument `open()` (e.g., `open(my $fh, '<', $file)`) to interpret the path explicitly.