What is CVE-2026-66901?
CVE-2026-66901 is a critical vulnerability in Google::Auth for Perl versions prior to 0.09, allowing Server-Side Request Forgery (SSRF) and credential exfiltration due to unvalidated URLs from the credentials JSON. Affected systems should immediately upgrade the library to version 0.09 or later to mitigate the risk.
Azərbaycanca: CVE-2026-66901, Google::Auth Perl kitabxanasının 0.09-dan əvvəlki versiyalarında aşkarlanan kritik zəiflikdir. Bu qüsur, "credentials JSON" faylından oxunan URL-lərin "universe domain" ilə yoxlanılmaması səbəbindən server tərəfli sorğu saxtakarlığına (SSRF) və etimadnamələrin sızdırılmasına yol açır. Təsirə məruz qalan sistemlərdə kitabxananı dərhal 0.09 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918; shared vendor: Google
FAQ2
What is the root cause of the CVE-2026-66901 vulnerability?
The root cause of this vulnerability is that the Google::Auth Perl library does not properly validate URLs read from the credentials JSON file using the 'universe domain'.
How can I protect my system from CVE-2026-66901?
It is recommended to immediately upgrade the Google::Auth Perl library to version 0.09 or later on all affected systems.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.