Description
Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON.

The URLs the library requests are read from the credentials JSON, and their hosts were not checked against the universe domain before the request. For an external_account configuration, retrieve_subject_token fetched credential_source.url with headers from the same JSON, and fetch_access_token posted the subject token to token_url, then sent the STS access token it received to service_account_impersonation_url in an Authorization: Bearer header. The authorized_user, impersonated_service_account and service_account configurations posted the client secret and refresh token, the source access token, and a signed JWT assertion to their own JSON-supplied token_uri or impersonation URL.

Any caller that builds credentials from a configuration it does not fully control issues those requests from the application's network position, reaching hosts the configuration names, including internal services and link-local metadata endpoints, and hands them the credentials each request carries. The service_account assertion is bound to aud, so it is not replayable against Google.

Version 0.06 added a _validate_url host check to the external_account class, keyed on a universe_domain read from the same credentials JSON. Version 0.07 gated a JSON-supplied universe domain behind GOOGLE_EXTERNAL_ACCOUNT_ALLOW_CUSTOM_UNIVERSES=1, deriving the pin flag from arguments that an earlier BUILDARGS pass had already merged on the make_creds path. Version 0.08 passed the pin decision through as an explicit constructor argument and moved _validate_url to Google::Auth::Credentials, adding the call to UserRefreshCredentials and ImpersonatedServiceAccountCredentials, and 0.09 added it to ServiceAccountCredentials.
Published: 2026-08-04
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Google::Auth for Perl versions earlier than 0.09 can expose credentials and facilitate server-side request forgery because the library accepts URL values directly from the credentials JSON and sends network requests to those hosts without validation. An attacker who can influence the credentials configuration may force the application to reach internal or external services, and the requests carry sensitive tokens or secrets that the application holds. This flaw allows credential exfiltration and can compromise the confidentiality of service account keys, user secrets, or other privileged data.

Affected Systems

Systems that use the Perl package CJCOLLIER::Google::Auth with a version before 0.09 are vulnerable. The issue was addressed in version 0.09, which validates each request host against the standard googleapis.com domain or a universe domain that the application pins. Administrators should review any deployment that imports credentials JSON into the library, particularly in environments using external_account, authorized_user, impersonated_service_account, or service_account configurations.

Risk and Exploitability

The vulnerability has no publicly reported exploit, but it is a high-risk server-side request forgery that can lead to data theft or unauthorized service calls. With an EPSS score not available and the vulnerability not listed in CISA KEV catalog, the exact likelihood of exploitation remains unknown, yet the severity is high due to the potential for credential leakage. An attacker with control over the credentials JSON can execute arbitrary network requests from the application’s network position, including accessing internal metadata endpoints and exfiltrating credentials that are automatically attached to outgoing HTTP requests by the library.

Generated by OpenCVE AI on August 4, 2026 at 22:41 UTC.

Remediation

Vendor Solution

Upgrade to Google-Auth 0.09 or later, which validates each URL host against googleapis.com or a universe domain pinned by the application before the request.


Vendor Workaround

For deployments that cannot upgrade to 0.09, ensure that every credentials configuration reaching the Application Default Credentials flow comes from a trusted source.


OpenCVE Recommended Actions

  • Upgrade CJCOLLIER::Google::Auth to version 0.09 or newer, which validates each request host before making outbound requests.
  • If upgrading is not yet possible, restrict the source of any credentials JSON fed into the library to trusted, immutable configuration files, ensuring that no external parties can alter URLs.
  • When using older versions, manually audit the credentials JSON to confirm that all token_uri, impersonation_url, and subject_token_url values resolve only to googleapis.com or a known universe domain, and block or remove any other entries.

Generated by OpenCVE AI on August 4, 2026 at 22:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON. The URLs the library requests are read from the credentials JSON, and their hosts were not checked against the universe domain before the request. For an external_account configuration, retrieve_subject_token fetched credential_source.url with headers from the same JSON, and fetch_access_token posted the subject token to token_url, then sent the STS access token it received to service_account_impersonation_url in an Authorization: Bearer header. The authorized_user, impersonated_service_account and service_account configurations posted the client secret and refresh token, the source access token, and a signed JWT assertion to their own JSON-supplied token_uri or impersonation URL. Any caller that builds credentials from a configuration it does not fully control issues those requests from the application's network position, reaching hosts the configuration names, including internal services and link-local metadata endpoints, and hands them the credentials each request carries. The service_account assertion is bound to aud, so it is not replayable against Google. Version 0.06 added a _validate_url host check to the external_account class, keyed on a universe_domain read from the same credentials JSON. Version 0.07 gated a JSON-supplied universe domain behind GOOGLE_EXTERNAL_ACCOUNT_ALLOW_CUSTOM_UNIVERSES=1, deriving the pin flag from arguments that an earlier BUILDARGS pass had already merged on the make_creds path. Version 0.08 passed the pin decision through as an explicit constructor argument and moved _validate_url to Google::Auth::Credentials, adding the call to UserRefreshCredentials and ImpersonatedServiceAccountCredentials, and 0.09 added it to ServiceAccountCredentials.
Title Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON
Weaknesses CWE-201
CWE-918
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-08-04T22:24:40.149Z

Reserved: 2026-07-28T08:28:27.249Z

Link: CVE-2026-66901

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T22:45:03Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data

  • CWE-918

    Server-Side Request Forgery (SSRF)