Dancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verification disabled.
The default user agent is initialised with SSL_verify_mode explicitly disabled.
An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token exchange and userinfo fetch, return a forged access_token and user profile, and be logged in to the Dancer application as any Google user.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Aug 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled. The default user agent is initialised with SSL_verify_mode explicitly disabled. An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token exchange and userinfo fetch, return a forged access_token and user profile, and be logged in to the Dancer application as any Google user. | Dancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verification disabled. The default user agent is initialised with SSL_verify_mode explicitly disabled. An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token exchange and userinfo fetch, return a forged access_token and user profile, and be logged in to the Dancer application as any Google user. |
| Title | Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled | Dancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verification disabled |
| References |
|
Thu, 23 Jul 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Garu
Garu dancer::plugin::auth::google |
|
| Vendors & Products |
Garu
Garu dancer::plugin::auth::google |
Fri, 17 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 17 Jul 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled. The default user agent is initialised with SSL_verify_mode explicitly disabled. An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token exchange and userinfo fetch, return a forged access_token and user profile, and be logged in to the Dancer application as any Google user. | |
| Title | Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled | |
| Weaknesses | CWE-295 | |
| References |
|
Status: PUBLISHED
Assigner: CPANSec
Published: 2026-07-17T12:50:30.389Z
Updated: 2026-08-11T18:02:06.250Z
Reserved: 2026-06-26T10:06:50.040Z
Link: CVE-2026-13410
Updated: 2026-07-17T15:28:12.202Z
Status : Deferred
Published: 2026-07-17T13:17:56.663
Modified: 2026-08-11T18:17:19.290
Link: CVE-2026-13410
No data.