Vulnerability in Punk::OAuth2 for Perl Allows Off-Site Redirects
CVE-2026-75628
Currently unrated
What is CVE-2026-75628?
A vulnerability in Punk::OAuth2 for Perl allows attackers to leverage an improper validation of the return parameter during the login process. The flawed check permits backslashes and tabs, which could be exploited to redirect users to a malicious site after they authenticate. This bypass allows crafted links to redirect users to an attacker's site without carrying an authorization code or access token, compromising the security of the user session.
