9.1
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Description
Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce.
The default nonce was generated using an MD5 hash of the epoch time, which is predictable.
The default nonce was generated using an MD5 hash of the epoch time, which is predictable.
AI Analysis
Predictable nonce vulnerability in Dancer2::Plugin::Auth::OAuth before version 0.22
Basic Information
ID
CVE-2026-11832
Source
CPANSec
Published
Jun 15, 2026 at 21:19
Modified
Jun 16, 2026 at 16:05
Affected Product
Vendor
BIAFRA
Product
Dancer2::Plugin::Auth::OAuth
Affected Versions
BIAFRA Dancer2::Plugin::Auth::OAuth 0
CWE Classification
AI Assessment
AI Score
9.1 / 10
AI Severity
Critical
Vendor
BIAFRA
Product
Dancer2::Plugin::Auth::OAuth
Version
< 0.22