CPANSA-Plack-Middleware-OAuth-2026-12740: Plack-Middleware-OAuth vulnerability
| Publisher | giterlizzi | Document category | csaf_security_advisory |
|---|---|---|---|
| Initial release date | 2026-07-04T00:00:00 | Engine | CSAF Perl Toolkit 0.26 |
| Current release date | 2026-07-04T00:00:00 | Build Date | |
| Current version | 1 | Status | final |
| CVSS v3.1 Base Score | 8.1 | Severity | |
| Original language | Language | en | |
| Also referred to | |||
Vulnerability Description
Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter. RequestTokenV2 builds the provider authorization redirect without issuing a state value, and AccessTokenV2 exchanges the callback code and registers the resulting token into the session (register_session) without verifying that the callback corresponds to an authorization request this session initiated. Any application that uses this middleware for OAuth 2.0 login is exposed to login cross-site request forgery: because the callback is not bound to the session that began the flow, an attacker who starts an authorization with their own provider account can deliver the resulting callback to a victim, causing the victim's session to complete the attacker's authorization and associating the attacker's provider identity and access token with that session. Where the application persists this as an account link, the attacker may retain access to the victim's account through their own provider credentials.
Vulnerabilities
CVE-2026-12740
Vulnerability DescriptionPlack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter.
RequestTokenV2 builds the provider authorization redirect without issuing a state value, and AccessTokenV2 exchanges the callback code and registers the resulting token into the session (register_session) without verifying that the callback corresponds to an authorization request this session initiated.
Any application that uses this middleware for OAuth 2.0 login is exposed to login cross-site request forgery: because the callback is not bound to the session that began the flow, an attacker who starts an authorization with their own provider account can deliver the resulting callback to a victim, causing the victim's session to complete the attacker's authorization and associating the attacker's provider identity and access token with that session. Where the application persists this as an account link, the attacker may retain access to the victim's account through their own provider credentials.
| Weakness | CWE-352 : Cross-Site Request Forgery (CSRF) |
|---|
Product status
Known affected
| Product | Score | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Plack-Middleware-OAuth greater than 0 |
|
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-Plack-Middleware-OAuth-2026-12740 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2026/cpansa-plack-middleware-oauth-2026-12740.json - https://datatracker.ietf.org/doc/html/rfc6749#section-10.12 external
https://datatracker.ietf.org/doc/html/rfc6749#section-10.12 - https://github.com/c9s/Plack-Middleware-OAuth/pull/13 external
https://github.com/c9s/Plack-Middleware-OAuth/pull/13 - https://rt.cpan.org/Ticket/Display.html?id=179874 external
https://rt.cpan.org/Ticket/Display.html?id=179874 - https://security.metacpan.org/patches/P/Plack-Middleware-OAuth/0.10/CVE-2026-12740-r1.patch external
https://security.metacpan.org/patches/P/Plack-Middleware-OAuth/0.10/CVE-2026-12740-r1.patch - http://www.openwall.com/lists/oss-security/2026/07/04/10 external
http://www.openwall.com/lists/oss-security/2026/07/04/10 - CVE-2026-12740 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2026-12740
Revision history
| Version | Date of the revision | Summary of the revision |
|---|---|---|
| 1 | Sat Jul 4 00:00:00 2026 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/