Executive brief
A security vulnerability exists in a Perl library used for handling OAuth2 authentication in web applications. The software uses a predictable method to generate security tokens, which could allow an attacker to trick a user into performing unintended actions or hijack their login session. This puts user accounts and sensitive data at risk of unauthorized access.
Technical details
The Mojolicious::Plugin::Web::Auth::OAuth2 module (versions <= 0.17) contains a vulnerability where the default OAuth2 'state' parameter is generated using low-entropy, predictable sources. When no custom state generator is provided, the '_state_generator' function uses a SHA-1 hash of the current epoch time, the process ID, and Perl's built-in rand() function. Because the epoch time is often leaked via HTTP Date headers and the PRNG is not cryptographically secure, an attacker can predict the state value. This allows for successful Cross-Site Request Forgery (CSRF) attacks, potentially leading to session hijacking during the OAuth2 flow. A patch is available via MetaCPAN security advisories.
Affected products
- HAYAJO Mojolicious::Plugin::Web::Auth::OAuth2 through 0.17
Timeline
- 2026-06-23: disclosed: CVE published to NVD