CVE-2026-12740
CORNELIUS Plack::Middleware::OAuth
Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter. RequestTokenV2 builds the provider authorization redirect without issuing a state value, and AccessTokenV2 exchanges the callback code and registers the resulting token into the session (register_session) without verifying that the callback corresponds to an authorization request this session initiated. Any application that uses this middleware for OAuth 2.0 login is exposed to login cross-site request forgery: because the callback is not bound to the session that began the flow, an attacke...
- CVSS
- 8.1
- EPSS
- 0.17% 6.83% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.05