Search
Find merged stories by title or summary.
CVE-2026-72887 - Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token
CVE ID : CVE-2026-72887 Published : Aug. 16, 2026, 2:16 p. m. • 6 hours, 50 minutes ago Description : Net::OAuth::Client versions before 0. 32 for Perl allow the service provider to silently downgrade OAuth 1. 0a to OAuth 1. 0 in get_request_token. Passing a callback to the constructor selects OAuth 1. 0a. get_request_token then revokes that choice when the request token response omits oauth_callback_confirmed, with no exception, no warning and no option to require 1. 0a. The access token request is built from the OAuth 1. 0 message class, which has no verifier parameter, so oauth_verifier is dropped from the request even when get_access_token was passed one. oauth_verifier is the binding that OAuth 1. 0a added between the authorization step and the token exchange. An application that asked for 1. 0a and gets 1. 0 is open to OAuth 1.
cve-2026-72887
Net::OAuth::Client versions before 0. 32 for Perl allow the service provider to silently downgrade OAuth 1. 0a to OAuth 1. 0 in get_request_token
You've reached the end of current stories for this search.
