VYPR

MojoX::Authentication

by MojoX

CVEs (1)

  • CVE-2026-86304CriSep 6, 2026
    risk 0.57cvss 9.8epss 0.00

    MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor. parse_assertion in MojoX::Authentication::Model::SAML2 calls Net::SAML2::Binding::POST->new with no cacert,…