High severity8.2NVD Advisory· Published Jul 17, 2026· Updated Aug 11, 2026
CVE-2026-13410
CVE-2026-13410
Description
Dancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verification disabled.
The default user agent is initialised with SSL_verify_mode explicitly disabled.
An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token exchange and userinfo fetch, return a forged access_token and user profile, and be logged in to the Dancer application as any Google user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <0.07
Patches
Vulnerability mechanics
References
6- www.openwall.com/lists/oss-security/2026/07/17/8nvd
- github.com/garu/Dancer-Plugin-Auth-Google/commit/2fdb72527eaa0e11a5c134c597f1e44e37411d95.patchnvd
- github.com/garu/Dancer-Plugin-Auth-Google/pull/5nvd
- metacpan.org/pod/Furlnvd
- metacpan.org/release/GARU/Dancer-Plugin-Auth-Google-0.08/changesnvd
- security.metacpan.org/patches/D/Dancer-Plugin-Auth-Google/0.07/CVE-2026-13410-r1.patchnvd
News mentions
0No linked articles in our index yet.