rpm package
opensuse/perl-Net-OAuth&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/perl-Net-OAuth&distro=openSUSE%20Tumbleweed
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-75589 | Hig | 7.5 | < 0.330.0-1.1 | 0.330.0-1.1 | Aug 19, 2026 | Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify. Each of the three compares the signature carried in the message against the locally computed one with the eq operator, which returns as s | |
| CVE-2026-72889 | Cri | 9.8 | < 0.330.0-1.1 | 0.330.0-1.1 | Aug 19, 2026 | Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify. verify resolves the signature method class from the signature_method parameter of the incoming message. signature_method is required on every request, so the algorithm used to | |
| CVE-2026-72888 | Med | 6.5 | < 0.330.0-1.1 | 0.330.0-1.1 | Aug 16, 2026 | Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require. smart_require stores results in a process-global hash with no bound and no eviction, and keeps an entry for every class name it is asked about, includi | |
| CVE-2026-72887 | Cri | 9.8 | < 0.330.0-1.1 | 0.330.0-1.1 | Aug 16, 2026 | Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token. Passing a callback to the constructor selects OAuth 1.0a. get_request_token then revokes that choice when the request token response om |
- affected < 0.330.0-1.1fixed 0.330.0-1.1
Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify. Each of the three compares the signature carried in the message against the locally computed one with the eq operator, which returns as s
- affected < 0.330.0-1.1fixed 0.330.0-1.1
Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify. verify resolves the signature method class from the signature_method parameter of the incoming message. signature_method is required on every request, so the algorithm used to
- affected < 0.330.0-1.1fixed 0.330.0-1.1
Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require. smart_require stores results in a process-global hash with no bound and no eviction, and keeps an entry for every class name it is asked about, includi
- affected < 0.330.0-1.1fixed 0.330.0-1.1
Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token. Passing a callback to the constructor selects OAuth 1.0a. get_request_token then revokes that choice when the request token response om