s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVE-2026-95831

📛 CVE Title

Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL

Description

Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts to retrieve code from a hardcoded http URL that is obfuscated with base64 encoding and run the response body directly. The impact is that arbitrary code can be invoked as the user, without a dropped script being saved on the affected host. The releases have no test scripts nor build hooks. The intention may have been to trigger the payload after installation. For version 1.01, the dropper script is in lib/Crypt/SelfCertificate/sample/validate.p12. For version 1.05, the dropper script is in lib/Crypt/SelfCertificate/sample/cert7.pem. The SHA-256 digests of the files are fbff21f45ff748365062a5e36fb2d72558cad82a507a6f357f320b4fcdf07760 Crypt-SelfCertificate-1.01.tar.gz 27b2d2d3174ad771474fff2521f5084ec231e9218ea8c832515aef1cbd5897bc lib/Crypt/SelfCertificate/sample/validate.p12 9fdfa7d69b034b77d4510cda567e8da1e486ca81c7daaadc5732a45c41d71991 Crypt-SelfCertificate-1.05.tar.gz 27b2d2d3174ad771474fff2521f5084ec231e9218ea8c832515aef1cbd5897bc lib/Crypt/SelfCertificate/sample/cert7.pem

Overview

State
PUBLISHED
Assigner (CNA)
CPANSec
CVSS severity
—
CVSS score
—
CVSS vector
—
Effective score
7.8 / 10 HIGH source: NVD
CWE(s)
CWE-506
Reserved
2026-09-22
Published
2026-09-22 18:21 UTC
Last updated
2026-09-23 16:09 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/95xxx/CVE-2026-95831.json
Linked Threat
CVE-2026-95831 — Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2026-09-22 19:17:00 UTC
NVD last modified
2026-09-22 21:17:34 UTC
NVD CVSS v3.1
CVSS 7.8 / 10 7.8 7.8 / 10 HIGH source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
NVD CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability subscore
1.8 / 10
Impact subscore
5.9 / 10

NVD / KEV / EPSS data refreshed 2026-09-23 02:28 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2026-84745
Assigner
CPANSec
Published
Sep 22, 2026, 6:21:23 PM
Updated
Sep 23, 2026, 3:09:27 AM
EUVD base score (CVSS 3.1)
7.8 / 10
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EUVD-reported EPSS
0.0000
Aliases
GHSA-9ppr-x3mg-6jg2

ENISA description: Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts to retrieve code from a hardcoded http URL that is obfuscated with base64 encoding and run the response body directly. The impact is that arbitrary code can be invoked as the user, without a dropped script being saved on the affected host. The releases have no test scripts nor build hooks. The intention may have been to trigger the payload after installation. For version 1.01, the dropper script is in lib/Crypt/SelfCertificate/sample/validate.p12. For version 1.05, the dropper script is in lib/Crypt/SelfCertificate/sample/cert7.pem. The SHA-256 digests of the files are fbff21f45ff748365062a5e36fb2d72558cad82a507a6f357f320b4fcdf07760 Crypt-SelfCertificate-1.01.tar.gz 27b2d2d3174ad771474fff2521f5084ec231e9218ea8c832515aef1cbd5897bc lib/Crypt/SelfCertificate/sample/validate.p12 9fdfa7d69b034b77d4510cda567e8da1e486ca81c7daaadc5732a45c41d71991 Crypt-SelfCertificate-1.05.tar.gz 27b2d2d3174ad771474fff2521f5084ec231e9218ea8c832515aef1cbd5897bc lib/Crypt/SelfCertificate/sample/cert7.pem

EUVD references (1)

Affected products (1)

VendorProductVersionsPlatforms
— — 1.01 (affected) —

Vendor references (1)

References embedded in the original CVE record by the assigning CNA.

Web references (0)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

No web references attached yet.

NVD-tagged references (2)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Remediations (20)

Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

  • web:fix-it-up.fandom.com

    Home Welcome to the Official Fix It Up Wiki! This community wiki is dedicated to helping both new and experienced mechanics in the Roblox game Fix It Up!. Here you will find information about repairing cars, upgrading tools, customizing vehicles, and mastering the game.

    2026-09-23 15:40 UTC
  • web:patch.com

    The best breaking news, stories, and events from the Patch network of local news sites

    2026-09-23 15:40 UTC
  • web:patch.com

    Tinley Park Latest Headlines: Caller Claimed To Have Gun, Homemade Bomb Inside Oak Forest HS, Threatened To Shoot Up School: Police; 🌱 Patch AM: How new Harmony Square parking rules could ...

    2026-09-23 15:40 UTC
  • web:stockanalysis.com

    About FIX Comfort Systems USA, Inc., together with its subsidiaries, provides mechanical and electrical installation, renovation, maintenance, repair, and replacement services for the mechanical and electrical services industry in the United States. The company operates through two segments: Mechanical and Electrical. It offers heating, ventilation, and air conditioning systems, as well as ...

    2026-09-23 15:40 UTC
  • web:www.fix.com

    Fix .com is a one-stop source for fixing products in and around your home. Millions of quality OEM replacement parts, repair videos, instructions, and same-day shipping available!

    2026-09-23 15:40 UTC
  • web:www.golfthepatch.com

    Now open, The Patch features a redesigned 18-hole course, led by golf course architects Tom Fazio and Beau Welling, and a new 9-hole short course, The Loop at The Patch , designed by Tiger Woods and TGR Design. Welcome to Augusta's best-in-class public golf experience.

    2026-09-23 15:40 UTC
  • web:www.ifixit.com

    iFixit is a global community of people helping each other repair things. Let's fix the world, one device at a time. Troubleshoot with experts in the Answers forum—and build your own how-to guides to share with the world. Fix your Apple and Android devices—and buy all the parts and tools needed for your DIY repair projects.

    2026-09-23 15:40 UTC
  • web:www.kaguragames.com

    3. Click "Next" 2 more times. After the patch is finished installing, your game should now be patched.

    2026-09-23 15:40 UTC
  • web:www.patch.io

    Patch is the AI-native services company for environmental markets. One platform for carbon, RECs, and SAFc — embedded experts, proprietary data, built-in AI.

    2026-09-23 15:40 UTC
  • web:www.wordwebonline.com

    Verb: fix fiks Restore by replacing a part or putting together what is torn or broken "She fixed her laptop "; - repair, mend, bushel [US], doctor [informal] Cause to be firmly attached "she fixed her gaze on the man"; - fasten, secure Establish or state a specific value or set of values " fix the variables "; - specify, set, determine, define, limit Make fixed, stable or stationary "let's fix ...

    2026-09-23 15:40 UTC
  • web:blog.gridinsoft.com

    Cisco FMC attacks led to credential theft and Qilin ransomware. Check current fixed releases, rotated logs and Cisco recovery guidance for suspected compromise.

    2026-09-25 10:07 UTC
  • web:directaccess.richardhicks.com

    Microsoft released the September 2026 security updates today, which include numerous fixes affecting Always On VPN deployments. This month's edition addresses vulnerabilities in Windows Server Routing and Remote Access (RRAS), VPN protocols such as Secure Socket Tunneling Protocol (SSTP) and Internet Key Exchange version 2 (IKEv2). The updates also include Active Directory Certificate ...

    2026-09-25 10:07 UTC
  • web:github.com

    A community-curated, verified collection of Proof-of-Concept exploits for CVEs disclosed in 2026 .

    2026-09-25 10:07 UTC
  • web:patchmypc.com

    You can find the production release history below for 2026 .

    2026-09-25 10:07 UTC
  • web:radar.offseq.com

    Detailed information about CVE-2026-95831 : CWE-506 Embedded Malicious Code. Get real-time updates, technical details, and mitigation strategies.

    2026-09-25 10:07 UTC
  • web:sec.cloudapps.cisco.com

    On September 16, 2026 , the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables. To remediate these vulnerabilities, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the ...

    2026-09-25 10:07 UTC
  • web:tech-insider.org

    CISA confirms ransomware gangs are exploiting CVE - 2026 -59310, a CVSS 9.8 VMware vCenter RCE flaw. Patch details, KEV deadline, and fixes inside.

    2026-09-25 10:07 UTC
  • web:windowsforum.com

    Microsoft tracked YellowKey as CVE - 2026 -45585 and initially issued a mitigation while it prepared a full update. The important date for administrators is June 9, 2026 : Microsoft included a fix in its June Patch Tuesday security releases.

    2026-09-25 10:07 UTC
  • web:www.cvefind.com

    CVE Find is a real-time vulnerability database indexing 397 450 security flaws ( CVE ) from MITRE, NVD, CISA KEV, CWE and CAPEC. 2503 new CVEs were published in the last 7 days. Data aggregated from: MITRE Corporation ( CVE , CWE, CAPEC), National Vulnerability Database - NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).

    2026-09-25 10:07 UTC
  • web:www.youtube.com

    © 2026 Google LLC

    2026-09-25 10:07 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2026-95831.json.

{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2026-09-23T16:09:02.987Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "http://www.openwall.com/lists/oss-security/2026/09/22/21"
          },
          {
            "url": "http://www.openwall.com/lists/oss-security/2026/09/23/2"
          },
          {
            "url": "http://www.openwall.com/lists/oss-security/2026/09/23/3"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "LOCAL",
              "availabilityImpact": "HIGH",
              "baseScore": 7.8,
              "baseSeverity": "HIGH",
              "confidentialityImpact": "HIGH",
              "integrityImpact": "HIGH",
              "privilegesRequired": "NONE",
              "scope": "UNCHANGED",
              "userInteraction": "REQUIRED",
              "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2026-95831",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-22T20:13:35.298576Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-22T20:13:37.851Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "collectionURL": "https://cpan.org/modules",
          "defaultStatus": "unaffected",
          "modules": [
            "Crypt::SelfCertificate"
          ],
          "packageName": "Crypt-SelfCertificate",
          "packageURL": "pkg:cpan/Crypt-SelfCertificate",
          "programFiles": [
            "lib/Crypt/SelfCertificate.pm",
            "lib/Crypt/SelfCertificate/sample/validate.p12",
            "lib/Crypt/SelfCertificate/sample/cert7.pem"
          ],
          "versions": [
            {
              "lessThanOrEqual": "1.05",
              "status": "affected",
              "version": "1.01",
              "versionType": "custom"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL.\n\nThe generate_certificate runs a Python script saved as a certificate file.  The pyhton script attempts to retrieve code from a hardcoded http URL that is obfuscated with base64 encoding and run the response body directly.\n\nThe impact is that arbitrary code can be invoked as the user, without a dropped script being saved on the affected host.\n\nThe releases have no test scripts nor build hooks.  The intention may have been to trigger the payload after installation.\n\nFor version 1.01, the dropper script is in lib/Crypt/SelfCertificate/sample/validate.p12.\n\nFor version 1.05, the dropper script is in lib/Crypt/SelfCertificate/sample/cert7.pem.\n\nThe SHA-256 digests of the files are\n\n    fbff21f45ff748365062a5e36fb2d72558cad82a507a6f357f320b4fcdf07760 Crypt-SelfCertificate-1.01.tar.gz\n    27b2d2d3174ad771474fff2521f5084ec231e9218ea8c832515aef1cbd5897bc lib/Crypt/SelfCertificate/sample/validate.p12\n\n    9fdfa7d69b034b77d4510cda567e8da1e486ca81c7daaadc5732a45c41d71991 Crypt-SelfCertificate-1.05.tar.gz\n    27b2d2d3174ad771474fff2521f5084ec231e9218ea8c832515aef1cbd5897bc lib/Crypt/SelfCertificate/sample/cert7.pem"
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-253",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-253 Remote Code Inclusion"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-506",
              "description": "CWE-506 Embedded Malicious Code",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-22T18:21:23.728Z",
        "orgId": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
        "shortName": "CPANSec"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://www.nntp.perl.org/group/perl.cpan.testers.discuss/2026/09/msg4754.html"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "value": "Systems on which the affected package was installed should be considered potentially compromised and investigated accordingly."
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "timeline": [
        {
          "lang": "en",
          "time": "2026-09-15T00:00:00.000Z",
          "value": "Crypt::SelfCertificate version 1.00 uploaded to CPAN"
        },
        {
          "lang": "en",
          "time": "2026-09-17T00:00:00.000Z",
          "value": "Crypt::SelfCertificate version 1.01 uploaded to CPAN"
        },
        {
          "lang": "en",
          "time": "2026-09-22T00:00:00.000Z",
          "value": "Crypt::SelfCertificate version 1.05 uploaded to CPAN"
        },
        {
          "lang": "en",
          "time": "2026-09-22T00:00:00.000Z",
          "value": "Malware identified by CPANSec scanning"
        }
      ],
      "title": "Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL",
      "x_generator": {
        "engine": "cpansec-cna-tool 0.1"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
    "assignerShortName": "CPANSec",
    "cveId": "CVE-2026-95831",
    "datePublished": "2026-09-22T18:21:23.728Z",
    "dateReserved": "2026-09-22T16:29:23.694Z",
    "dateUpdated": "2026-09-23T16:09:02.987Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}