CVE-2026-7381
Attacker can rewrite file paths to gain control of your server.
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A critical flaw in Plack::Middleware::XSendfile lets attackers read any file on your server by tricking it into rewriting paths, potentially exposing sensitive data from internet-facing web applications.