CVE-2013-10031

Dec. 9, 2025, 6:37 p.m.

None
No Score

Description

Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks

Product(s) Impacted

Vendor Product Versions
Plack
  • Plack-middleware-session
  • <0.17

Weaknesses

Common security weaknesses mapped to this vulnerability.

CWE-1254
Incorrect Comparison Logic Granularity
The product's comparison logic is performed over a series of steps rather than across the entire string in one operation. If there is a comparison logic failure on one of these steps, the operation may be vulnerable to a timing attack that can result in the interception of the process for nefarious purposes.

*CPE(s)

Affected systems and software identified for this CVE.

Type Vendor Product Version Update Edition Language Software Edition Target Software Target Hardware Other Information
a plack plack-middleware-session <0.17 / / / / / / /

Timeline

Published: Dec. 9, 2025, 1:16 a.m.
Last Modified: Dec. 9, 2025, 6:37 p.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

9b29abf9-4ab0-4765-b253-1875cd9b441e

*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.