THREAT OPS › Threat News › CVE-2026-75628: Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_path accepts a backslash or tab in the return parameter
CVE-2026-75628: Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_path accepts a backslash or tab in the return parameter
<p>Posted by Timothy Legge on Aug 19</p>========================================================================<br /> CVE-2026-75628 CPAN Security Group<br /> ========================================================================<br /> <br /> CVE ID: CVE-2026-75628<br /> Distribution: Punk-OAuth2<br /> Versions: before 0.03<br /> <br /
Indicators of compromise
- CVE-2026-75628cve
- https://metacpan.org/dist/Punk-OAuth2url
Original source: https://seclists.org/oss-sec/2026/q3/522