What is CVE-2026-72889?
In Net::OAuth for Perl versions before 0.33, the sender can choose the signature algorithm via the signature_method parameter during signature verification. This may allow an attacker to bypass authentication by forcing a weaker algorithm. Update Net::OAuth to version 0.33 or later immediately.
Azərbaycanca: Net::OAuth (Perl üçün) 0.33-dən əvvəlki versiyalarda imza yoxlanışı zamanı signature_method parametrini göndərənin seçməsinə icazə verilir. Bu, təcavüzkara zəif alqoritm təyin edərək autentifikasiyanı keçmək imkanı yarada bilər. Dərhal Net::OAuth kitabxanasını 0.33 və ya daha yeni versiyaya yeniləyin.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Through what mechanism in Net::OAuth does CVE-2026-72889 allow bypassing authentication?
During signature verification, the attacker can choose the `signature_method` parameter, which allows bypassing authentication by forcing a weaker algorithm.
To which version should one update to fix the CVE-2026-72889 vulnerability?
Update Net::OAuth to version 0.33 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.