VYPR

Plack::Middleware::OAuth

by Plack Project

CVEs (1)

  • CVE-2026-12740HigJul 4, 2026
    risk 0.46cvss 8.1epss 0.00

    Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter. RequestTokenV2 builds the provider authorization redirect without issuing a state value, and AccessTokenV2 exchanges the callback code and registers the resulting token into…