THREAT OPS › Threat News › CVE-2026-72887: Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token
CVE-2026-72887: Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token
<p>Posted by Robert Rothenberg on Aug 16</p>========================================================================<br /> CVE-2026-72887 CPAN Security Group<br /> ========================================================================<br /> <br /> CVE ID: CVE-2026-72887<br /> Distribution: Net-OAuth<br /> Versions: before 0.32<br /> <br
Indicators of compromise
- CVE-2026-72887cve
- https://metacpan.org/dist/Net-OAuthurl
Original source: https://seclists.org/oss-sec/2026/q3/506