THREAT OPS › Threat News › CVE-2026-66901: Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON
CVE-2026-66901: Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON
<p>Posted by Robert Rothenberg on Aug 04</p>========================================================================<br /> CVE-2026-66901 CPAN Security Group<br /> ========================================================================<br /> <br /> CVE ID: CVE-2026-66901<br /> Distribution: Google-Auth<br /> Versions: before 0.09<br /> <
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-66901cve
- https://metacpan.org/dist/Google-Authurl
Original source: https://seclists.org/oss-sec/2026/q3/434