VYPR

Net-OAuth

by Vurtdev

Source repositories

CVEs (4)

  • CVE-2026-72889CriAug 19, 2026
    risk 0.57cvss 9.8epss 0.00

    Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify. verify resolves the signature method class from the signature_method parameter of the incoming message. signature_method is required on every request, so the algorithm used to…

  • CVE-2026-72887CriAug 16, 2026
    risk 0.57cvss 9.8epss 0.01

    Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token. Passing a callback to the constructor selects OAuth 1.0a. get_request_token then revokes that choice when the request token response…

  • CVE-2026-75589HigAug 19, 2026
    risk 0.42cvss 7.5epss 0.01

    Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify. Each of the three compares the signature carried in the message against the locally computed one with the eq operator, which returns as…

  • CVE-2026-72888MedAug 16, 2026
    risk 0.35cvss 6.5epss 0.01

    Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require. smart_require stores results in a process-global hash with no bound and no eviction, and keeps an entry for every class name it is asked about,…

VYPR — Vulnerability Intelligence