Nonce Predictability in Dancer2::Plugin::Auth::OAuth for Perl
CVE-2026-11832
9.1CRITICAL
What is CVE-2026-11832?
The Dancer2::Plugin::Auth::OAuth versions prior to 0.22 exhibit a vulnerability where the nonce generation mechanism relies on an MD5 hash of the epoch time, making it predictable. This predictability can allow attackers to replay requests, compromising the integrity and confidentiality of OAuth transactions.
Affected Version(s)
Dancer2::Plugin::Auth::OAuth 0 < 0.22
