← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 16, 2026 · 14:16via CVEFeed

CVE-2026-72887 - Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token

Brief

CVE ID : CVE-2026-72887

Published : Aug. 16, 2026, 2:16 p. m.

  • 6 hours, 50 minutes ago

Description : Net::OAuth::Client versions before 0. 32 for Perl allow the service provider to silently downgrade OAuth 1. 0a to OAuth 1. 0 in get_request_token.

Passing a callback to the constructor selects OAuth 1. 0a. get_request_token then revokes that choice when the request token response omits oauth_callback_confirmed, with no exception, no warning and no option to require 1. 0a. The access token request is built from the OAuth 1. 0 message class, which has no verifier parameter, so oauth_verifier is dropped from the request even when get_access_token was passed one.

oauth_verifier is the binding that OAuth 1. 0a added between the authorization step and the token exchange. An application that asked for 1. 0a and gets 1. 0 is open to OAuth 1.

Read more on CVEFeed