VYPR

MojoX::Authentication

by Perl Foundation

CVEs (1)

  • CVE-2026-86304Sep 6, 2026
    risk 0.00cvss epss

    MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor. parse_assertion in MojoX::Authentication::Model::SAML2 calls Net::SAML2::Binding::POST->new with no cacert,…