Skip to content
TacitSoft Cyber Daily for 2026-08-22
TacitSoft Cyber Daily

Open-source authentication and input-handling disclosures

Punk authorization and session weaknesses lead this edition, alongside CHIRP radio-file code execution and Tie::Hash::Regex lookup-key exception handling.

Source-linked signals
4
Edition date
Aug 22, 2026
Coverage window
Complete UTC day
Vulnerabilities
RSS

Ranked operator signal

Signals in this edition

Each item links to its publisher and includes one independently written TacitSoft sentence based on structured facts.

Rank 01
Openwall oss-security Open Source Disclosure

[NotCVE-2026-0013] CHIRP Kenwood ITM Driver Eval Injection Allows Arbitrary Code Execution via Crafted Radio File

TacitSoft analysis

CHIRP users opening crafted radio files may face arbitrary code execution through the Kenwood ITM driver, so operators should treat untrusted radio files as executable input.

Read source
Rank 02
Openwall oss-security Open Source Disclosure

CVE-2026-75866: Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them

TacitSoft analysis

Perl applications using Punk::OAuth2::Server may issue access tokens beyond registered client scopes and grant types, so operators should review authorization boundaries for CVE-2026-75866.

Identifiers
CVE-2026-75866
Read source
Rank 03
Openwall oss-security Open Source Disclosure

CVE-2026-75870: Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared without a secret

TacitSoft analysis

Perl applications using Punk sessions may accept forged session cookies when no secret is configured, so operators should verify session HMAC keys for CVE-2026-75870.

Identifiers
CVE-2026-75870
Read source
Rank 04
Openwall oss-security Open Source Disclosure

CVE-2026-77781: Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys

TacitSoft analysis

Perl applications using Tie::Hash::Regex may encounter exceptions on unparseable lookup keys, so operators should test input handling while assessing CVE-2026-77781.

Identifiers
CVE-2026-77781
Read source

Get the briefing on your schedule

Choose daily, weekly, monthly, or any combination.

Choose your briefing cadence