CVSS 9.13 sources verified·1 min read
By Lyrie Threat Intelligence·5/8/2026
CRITICAL: CVE-2013-10075 (CVSS 9.1) — chorny apache\
CVE: CVE-2013-10075
CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity: CRITICAL
Status: Critical advisory
Affected
- chorny apache\
Summary
Apache::Session versions through 1.94 for Perl re-creates deleted sessions.
The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create a session that does not exist. This can lead to sessions being revived, potentially with data that was to be deleted.
Verified Sources
References
- https://rt.cpan.org/Public/Bug/Display.html?id=83525
- http://www.openwall.com/lists/oss-security/2026/05/08/12
_Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation._
Lyrie Verdict
A vulnerability of this severity is exactly what Lyrie's anti-rogue-AI defense is built for: continuous, autonomous monitoring that doesn't wait for human reaction time.
Validated sources
- [1]NVD
- [2]GitHub Advisory
- [3]MITRE