CVE-2026-11832
CRITICALDancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce
Title source: cnaDescription
Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was generated using an MD5 hash of the epoch time, which is predictable.
References (4)
Core 4
Core References
Release Notes release-notes
https://metacpan.org/release/BIAFRA/Dancer2-Plugin-Auth-OAuth-0.22/changes
Related related
https://www.cve.org/CVERecord?id=CVE-2025-22376
Scores
CVSS v3
9.1
EPSS
0.0033
EPSS Percentile
25.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-338
Status
published
Products (1)
BIAFRA/Dancer2::Plugin::Auth::OAuth
< 0.22
Published
Jun 15, 2026
Tracked Since
Jun 16, 2026