Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled.
The default user agent is initialised with SSL_verify_mode explicitly disabled.
An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token exchange and userinfo fetch, return a forged access_token and user profile, and be logged in to the Dancer application as any Google user.
The default user agent is initialised with SSL_verify_mode explicitly disabled.
An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token exchange and userinfo fetch, return a forged access_token and user profile, and be logged in to the Dancer application as any Google user.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
There is no caller-side override. Apply the patch.
References
History
Thu, 23 Jul 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Garu
Garu dancer::plugin::auth::google |
|
| Vendors & Products |
Garu
Garu dancer::plugin::auth::google |
Fri, 17 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 17 Jul 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled. The default user agent is initialised with SSL_verify_mode explicitly disabled. An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token exchange and userinfo fetch, return a forged access_token and user profile, and be logged in to the Dancer application as any Google user. | |
| Title | Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled | |
| Weaknesses | CWE-295 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-07-17T17:32:51.458Z
Reserved: 2026-06-26T10:06:50.040Z
Link: CVE-2026-13410
Updated: 2026-07-17T15:28:12.202Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-23T22:09:12Z
Weaknesses