Back

CRITICAL

Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter

Published Jun 23, 2026

Description

Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter.

When no state generator is specified in the constructor, the module defaults to using a SHA-1 hash of predictable and low-entropy sources, including the epoch time (which is leaked via the HTTP Date header) and a call to Perl's built-in rand function.

A predictable state allows an attacker to hijack another user's session through cross site request forgery (CSRF).

Affected products

Remediation

Vendor solution

Users should specify a state_generator function in the plugin configuration that uses a secure CSPRNG such as Crypt::PRNG or (for Mojolicious 9.46 or later) the Mojo::Util::random_bytes function. For example,

plugin 'Web::Auth', module => 'OAuth2', ... state_generator => sub { unpack("H*", Mojo::Util::random_bytes(20)) };

Weaknesses (2)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CPANSec
Published Jun 23, 2026
Updated Jun 23, 2026
Reserved May 27, 2026
CISA Vulnrichment
Updated Jun 23, 2026
NVD
Status Deferred
Modified Jun 23, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner CPANSec
Published Jun 23, 2026
Updated Jun 23, 2026
Exploited since n/a
EUVD-2026-38421