CVE Explorer
CVE-2026-12746
Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter.
The authentication_url method builds the provider authorization redirect without issuing a state value, and the callback method exchanges the callback code and registers the resulting token into the session without verifying that the callback corresponds to an authorization request this session initiated.
Any application that uses this plugin for OAuth 2.0 login is exposed to logi
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"collectionURL":"https://cpan.org/modules","defaultStatus":"unaffected","packageName":"Dancer2-Plugin-Auth-OAuth","product":"Dancer2::Plugin::Auth::OAuth::Provider","programFiles":["lib/Dancer2/Plugin/Auth/OAuth/Provider.pm"],"programRoutines":[{"name":"Dancer2::Plugin::Auth::OAuth::Provider::authentication_url"},{"name":"Dancer2::Plugin::Auth::OAuth::Provider::callback"}],"repo":"https://github.com/biafra/perl-Dancer2-Plugin-Auth-OAuth","vendor":"BIAFRA","versions":[{"lessThan":"0.23","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:cd2741f97d0d3da26e5d8712843285595f1d815b90c1e68e7043ae181575a434 · sha256:3b5cf8d89ce253a0… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":8.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:cd2741f97d0d3da26e5d8712843285595f1d815b90c1e68e7043ae181575a434 · sha256:3b5cf8d89ce253a0… · /containers/adp/1/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-352","description":"CWE-352 Cross-Site Request Forgery (CSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:cd2741f97d0d3da26e5d8712843285595f1d815b90c1e68e7043ae181575a434 · sha256:3b5cf8d89ce253a0… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"url":"http://www.openwall.com/lists/oss-security/2026/07/04/9"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:cd2741f97d0d3da26e5d8712843285595f1d815b90c1e68e7043ae181575a434 · sha256:3b5cf8d89ce253a0… · /containers/adp/0/references/0
{"tags":["technical-description"],"url":"https://datatracker.ietf.org/doc/html/rfc6749#section-10.12"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:cd2741f97d0d3da26e5d8712843285595f1d815b90c1e68e7043ae181575a434 · sha256:3b5cf8d89ce253a0… · /containers/cna/references/2
{"tags":["patch"],"url":"https://github.com/biafra/perl-Dancer2-Plugin-Auth-OAuth/commit/806420fc2abbe13bede4461475f2f3dcd7daf5f2.patch"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:cd2741f97d0d3da26e5d8712843285595f1d815b90c1e68e7043ae181575a434 · sha256:3b5cf8d89ce253a0… · /containers/cna/references/1
{"url":"https://metacpan.org/release/BIAFRA/Dancer2-Plugin-Auth-OAuth-0.23/diff/BIAFRA/Dancer2-Plugin-Auth-OAuth-0.22"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:cd2741f97d0d3da26e5d8712843285595f1d815b90c1e68e7043ae181575a434 · sha256:3b5cf8d89ce253a0… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.