The default nonce was generated using an MD5 hash of the epoch time, which is predictable.
Project Subscriptions
No data.
No advisories yet.
Solution
Upgrade to version 0.22 or later.
Workaround
No workaround given by the vendor.
Tue, 16 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 15 Jun 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was generated using an MD5 hash of the epoch time, which is predictable. | |
| Title | Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce | |
| Weaknesses | CWE-338 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-06-16T16:05:26.967Z
Reserved: 2026-06-09T21:09:06.279Z
Link: CVE-2026-11832
Updated: 2026-06-16T16:05:23.004Z
Status : Deferred
Published: 2026-06-15T22:16:15.400
Modified: 2026-06-16T15:41:12.897
Link: CVE-2026-11832
No data.
OpenCVE Enrichment
No data.