Junglewise Threat Intelligence

CVE-2026-13410: Dancer::Plugin::Auth::Google disabled TLS verification in OAuth2 exchange

CVE-2026-13410 · Severity: info · CVSS 0 · Published 2026-07-17

Executive brief

Dancer::Plugin::Auth::Google is a Perl library used to allow users to log into web applications using their Google accounts. A security flaw in this library disables encryption verification when communicating with Google's servers. This allows a well-positioned attacker to intercept the login process, impersonate any Google user, and gain unauthorized access to the application.

Technical details

Dancer::Plugin::Auth::Google (up to version 0.07) initializes its default user agent with SSL_verify_mode explicitly disabled. This improper certificate validation (CWE-295) occurs during the OAuth2 token exchange and userinfo fetch from googleapis.com. A network-based attacker capable of a Man-in-the-Middle (MITM) attack can intercept these requests and provide forged access tokens or user profiles. This allows the attacker to bypass authentication and log into the Dancer application as any arbitrary Google user. A patch has been proposed to enable proper SSL verification.

Affected products

  • GARU Dancer::Plugin::Auth::Google through 0.07

Timeline

  • 2026-07-17: disclosed
  • 2026-07-17: advisory

References