CVE-2026-9733
Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter.
When no state generator is specified in the constructor, the module defaults to using a SHA-1 hash of predictable and low-entropy sources, including the epoch time (which is leaked via the HTTP Date header) and a call to Perl's built-in rand function.
A predictable state allows an attacker to hijack another user's session through cross site request forgery (CSRF).
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
http://www.openwall.com/lists/oss-security/2026/06/23/1, https://cpan.org/modules, https://metacpan.org/release/HAYAJO/Mojolicious-Plugin-Web-Auth-0.17/source/lib/Mojolicious/Plugin/Web/Auth/OAuth2.pm#L129-131, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/9xxx/CVE-2026-9733.json, https://nvd.nist.gov/vuln/detail/CVE-2026-9733, https://security.metacpan.org/patches/M/Mojolicious-Plugin-Web-Auth/0.17/CVE-2026-9733-r2.patch, https://github.com/hayajo/Mojolicious-Plugin-Web-Auth, https://datatracker.ietf.org/doc/html/rfc6749#section-10.12