Signature Algorithm Selection Vulnerability in Net::OAuth for Perl
CVE-2026-72889

Currently unrated

Key Information:

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-72889?

The vulnerability in Net::OAuth for Perl revolves around inadequate signature validation, allowing an attacker to specify the signature algorithm for message verification. In versions preceding 0.33, the signature_method parameter is controlled by the sender, permitting them to dictate how the incoming message is validated. This flaw arises because the method to verify the signature can be easily manipulated, essentially letting an attacker forge requests using guessed signatures. For certain algorithms like HMAC-SHA1, the key derivation process does not adequately distinguish between different consumer keys, making it possible to exploit the weakness and authenticate fraudulent messages.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.