Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-9733

Gravedad CVSS v3.1:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
23/06/2026
Última modificación:
23/06/2026

Descripción

*** Pendiente de traducción *** Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter.<br /> <br /> When no state generator is specified in the constructor, the module defaults to using a SHA-1 hash of predictable and low-entropy sources, including the epoch time (which is leaked via the HTTP Date header) and a call to Perl&amp;#39;s built-in rand function.<br /> <br /> A predictable state allows an attacker to hijack another user&amp;#39;s session through cross site request forgery (CSRF).