The default user agent is initialised with SSL_verify_mode explicitly disabled.
An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token exchange and userinfo fetch, return a forged access_token and user profile, and be logged in to the Dancer application as any Google user.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
Upgrade to version 0.08 or later.
Workaround
For versions 0.07 or earlier, there is no caller-side override. Apply the patch.
Tue, 11 Aug 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled. The default user agent is initialised with SSL_verify_mode explicitly disabled. An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token exchange and userinfo fetch, return a forged access_token and user profile, and be logged in to the Dancer application as any Google user. | Dancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verification disabled. The default user agent is initialised with SSL_verify_mode explicitly disabled. An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token exchange and userinfo fetch, return a forged access_token and user profile, and be logged in to the Dancer application as any Google user. |
| Title | Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled | Dancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verification disabled |
| References |
|
Thu, 23 Jul 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Garu
Garu dancer::plugin::auth::google |
|
| Vendors & Products |
Garu
Garu dancer::plugin::auth::google |
Fri, 17 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 17 Jul 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled. The default user agent is initialised with SSL_verify_mode explicitly disabled. An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token exchange and userinfo fetch, return a forged access_token and user profile, and be logged in to the Dancer application as any Google user. | |
| Title | Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled | |
| Weaknesses | CWE-295 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-08-11T18:02:06.250Z
Reserved: 2026-06-26T10:06:50.040Z
Link: CVE-2026-13410
Updated: 2026-07-17T15:28:12.202Z
Status : Deferred
Published: 2026-07-17T13:17:56.663
Modified: 2026-08-11T18:17:19.290
Link: CVE-2026-13410
No data.
OpenCVE Enrichment
Updated: 2026-08-13T12:45:03Z