What is CVE-2026-72887?
CVE-2026-72887 is a vulnerability in Net::OAuth::Client for Perl prior to version 0.32, allowing a service provider to silently downgrade OAuth 1.0a to OAuth 1.0 via the get_request_token method. This bypasses the callback mechanism, potentially weakening authentication security. Users should update to the latest version to mitigate the issue.
Azərbaycanca: CVE-2026-72887, Perl üçün Net::OAuth::Client modulunun 0.32-dən əvvəlki versiyalarında OAuth 1.0a protokolunun xidmət təminatçısı tərəfindən səssiz şəkildə OAuth 1.0-a endirilməsinə imkan verən boşluqdur. Bu qüsur "get_request_token" funksiyası vasitəsilə callback təyinatını ləğv edir. Təsirə məruz qalan istifadəçilər modulu ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
What is CVE-2026-72887 and which Perl library does it affect?
CVE-2026-72887 is a vulnerability in the Net::OAuth::Client library for Perl prior to version 0.32, which allows a service provider to silently downgrade OAuth 1.0a to OAuth 1.0 via the `get_request_token` method.
How can users mitigate CVE-2026-72887?
To mitigate this vulnerability, users should update the Net::OAuth::Client module to the latest version (0.32 or newer).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.