Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled.

The default user agent is initialised with SSL_verify_mode explicitly disabled.

An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token exchange and userinfo fetch, return a forged access_token and user profile, and be logged in to the Dancer application as any Google user.
Advisories

No advisories yet.

Fixes

Solution

Upgrade to version 0.08 or later.


Workaround

For versions 0.07 or earlier, there is no caller-side override. Apply the patch.

History

Tue, 11 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Description Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled. The default user agent is initialised with SSL_verify_mode explicitly disabled. An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token exchange and userinfo fetch, return a forged access_token and user profile, and be logged in to the Dancer application as any Google user. Dancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verification disabled. The default user agent is initialised with SSL_verify_mode explicitly disabled. An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token exchange and userinfo fetch, return a forged access_token and user profile, and be logged in to the Dancer application as any Google user.
Title Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled Dancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verification disabled
References

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Garu
Garu dancer::plugin::auth::google
Vendors & Products Garu
Garu dancer::plugin::auth::google

Fri, 17 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Description Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled. The default user agent is initialised with SSL_verify_mode explicitly disabled. An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token exchange and userinfo fetch, return a forged access_token and user profile, and be logged in to the Dancer application as any Google user.
Title Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled
Weaknesses CWE-295
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-08-11T18:02:06.250Z

Reserved: 2026-06-26T10:06:50.040Z

Link: CVE-2026-13410

cve-icon Vulnrichment

Updated: 2026-07-17T15:28:12.202Z

cve-icon NVD

Status : Deferred

Published: 2026-07-17T13:17:56.663

Modified: 2026-08-11T18:17:19.290

Link: CVE-2026-13410

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T12:45:03Z

Weaknesses