CVE-2026-12740
Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-352
Falsificación de petición en sitios cruzados (Cross-Site Request Forgery)
Fecha de publicación:
04/07/2026
Última modificación:
06/07/2026
Descripción
*** Pendiente de traducción *** Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter.<br />
<br />
RequestTokenV2 builds the provider authorization redirect without issuing a state value, and AccessTokenV2 exchanges the callback code and registers the resulting token into the session (register_session) without verifying that the callback corresponds to an authorization request this session initiated.<br />
<br />
Any application that uses this middleware for OAuth 2.0 login is exposed to login cross-site request forgery: because the callback is not bound to the session that began the flow, an attacker who starts an authorization with their own provider account can deliver the resulting callback to a victim, causing the victim&#39;s session to complete the attacker&#39;s authorization and associating the attacker&#39;s provider identity and access token with that session. Where the application persists this as an account link, the attacker may retain access to the victim&#39;s account through their own provider credentials.
Impacto
Puntuación base 3.x
8.10
Gravedad 3.x
ALTA
Referencias a soluciones, herramientas e información
- https://datatracker.ietf.org/doc/html/rfc6749#section-10.12
- https://github.com/c9s/Plack-Middleware-OAuth/pull/13
- https://rt.cpan.org/Ticket/Display.html?id=179874
- https://security.metacpan.org/patches/P/Plack-Middleware-OAuth/0.10/CVE-2026-12740-r1.patch
- http://www.openwall.com/lists/oss-security/2026/07/04/10



