CPANSA-Dancer2-Plugin-Auth-OAuth-2026-11832: Dancer2-Plugin-Auth-OAuth vulnerability
| Publisher | giterlizzi | Document category | csaf_security_advisory |
|---|---|---|---|
| Initial release date | 2026-06-15T00:00:00 | Engine | CSAF Perl Toolkit 0.26 |
| Current release date | 2026-06-15T00:00:00 | Build Date | |
| Current version | 1 | Status | final |
| CVSS v3.1 Base Score | 9.1 | Severity | |
| Original language | Language | en | |
| Also referred to | |||
Vulnerability Description
Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was generated using an MD5 hash of the epoch time, which is predictable.
Vulnerabilities
CVE-2026-11832
Vulnerability DescriptionDancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce.
The default nonce was generated using an MD5 hash of the epoch time, which is predictable.
| Weakness | CWE-338 : Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) |
|---|
Product status
Known affected
| Product | Score | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Dancer2-Plugin-Auth-OAuth less than 0.22 |
|
Fixed
- Dancer2-Plugin-Auth-OAuth greater than or equal 0.22
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-Dancer2-Plugin-Auth-OAuth-2026-11832 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2026/cpansa-dancer2-plugin-auth-oauth-2026-11832.json - https://datatracker.ietf.org/doc/html/rfc5849#section-3.3 external
https://datatracker.ietf.org/doc/html/rfc5849#section-3.3 - https://datatracker.ietf.org/doc/html/rfc5849#section-4.9 external
https://datatracker.ietf.org/doc/html/rfc5849#section-4.9 - https://metacpan.org/release/BIAFRA/Dancer2-Plugin-Auth-OAuth-0.22/changes external
https://metacpan.org/release/BIAFRA/Dancer2-Plugin-Auth-OAuth-0.22/changes - https://www.cve.org/CVERecord?id=CVE-2025-22376 external
https://www.cve.org/CVERecord?id=CVE-2025-22376 - CVE-2026-11832 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2026-11832
Revision history
| Version | Date of the revision | Summary of the revision |
|---|---|---|
| 1 | Mon Jun 15 00:00:00 2026 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/