Junglewise Threat Intelligence

CVE-2026-9733: HAYAJO Mojolicious::Plugin::Web::Auth::OAuth2 Predictable State Parameter

CVE-2026-9733 · Severity: info · CVSS 0 · Published 2026-06-23

Executive brief

A security vulnerability exists in a Perl library used for handling OAuth2 authentication in web applications. The software uses a predictable method to generate security tokens, which could allow an attacker to trick a user into performing unintended actions or hijack their login session. This puts user accounts and sensitive data at risk of unauthorized access.

Technical details

The Mojolicious::Plugin::Web::Auth::OAuth2 module (versions <= 0.17) contains a vulnerability where the default OAuth2 'state' parameter is generated using low-entropy, predictable sources. When no custom state generator is provided, the '_state_generator' function uses a SHA-1 hash of the current epoch time, the process ID, and Perl's built-in rand() function. Because the epoch time is often leaked via HTTP Date headers and the PRNG is not cryptographically secure, an attacker can predict the state value. This allows for successful Cross-Site Request Forgery (CSRF) attacks, potentially leading to session hijacking during the OAuth2 flow. A patch is available via MetaCPAN security advisories.

Affected products

  • HAYAJO Mojolicious::Plugin::Web::Auth::OAuth2 through 0.17

Timeline

  • 2026-06-23: disclosed: CVE published to NVD

References