Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce.
The default nonce was generated using an MD5 hash of the epoch time, which is predictable.
The default nonce was generated using an MD5 hash of the epoch time, which is predictable.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to version 0.22 or later.
Workaround
No workaround given by the vendor.
References
History
Mon, 15 Jun 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was generated using an MD5 hash of the epoch time, which is predictable. | |
| Title | Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce | |
| Weaknesses | CWE-338 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-06-15T21:19:07.321Z
Reserved: 2026-06-09T21:09:06.279Z
Link: CVE-2026-11832
No data.
Status : Received
Published: 2026-06-15T22:16:15.400
Modified: 2026-06-15T22:16:15.400
Link: CVE-2026-11832
No data.
OpenCVE Enrichment
No data.
Weaknesses