THREATOPS
THREAT OPSThreat News › CVE-2026-66901: Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON

CVE-2026-66901: Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON

medoss_secPublished 2026-08-04

<p>Posted by Robert Rothenberg on Aug 04</p>========================================================================<br /> CVE-2026-66901                                       CPAN Security Group<br /> ========================================================================<br /> <br />         CVE ID:  CVE-2026-66901<br />   Distribution:  Google-Auth<br />       Versions:  before 0.09<br /> <

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/434