Description
Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require.

smart_require stores results in a process-global hash with no bound and no eviction, and keeps an entry for every class name it is asked about, including names that failed to load, because the return value of the failed eval is stored before the error is checked. The key comes off the wire on the server side: _signature_method_class builds the class name from the signature_method parameter of the incoming message, and verify resolves it before any signature is checked.

A remote client chooses both how many entries are created and how long each key is. In a persistent server the hash grows for the life of the worker process until it exhausts memory. Header size limits bound the key length on the Authorization header path, but not on a POST body.
Published: 2026-08-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is found in Net::OAuth versions prior to 0.32 for Perl. The smart_require routine stores the result of module load operations in a global hash without imposing any size limit or eviction policy, even when the load fails. Because the cache key is derived from the signature_method parameter supplied by an OAuth client, an attacker can trigger repeated failed loads of arbitrary class names. Each failed attempt reserves space in the hash, eventually exhausting the process memory and causing a denial of service.

Affected Systems

Perl applications that rely on Net::OAuth 0.30 or earlier to process OAuth requests, such as web services, APIs, or any server component that interprets the signature_method field from client messages. The issue is triggered when the server creates a class name from client data and attempts to load it; any application using the vulnerable library is at risk.

Risk and Exploitability

The flaw can be triggered remotely by any client able to send OAuth messages. By controlling the signature_method value and optionally the size of fields in the Authorization header or POST body, the attacker can determine the number and length of cache entries. The EPSS score is < 1% and the CVSS score is 6.5; despite the moderate severity, the unbounded memory growth presents a high likelihood of causing service interruption for long‑running workers. The vulnerability is not yet listed in the CISA KEV catalog, but the lack of bounds makes it a significant denial‑of‑service risk.

Generated by OpenCVE AI on August 17, 2026 at 18:47 UTC.

Remediation

Vendor Solution

Upgrade to Net-OAuth 0.32 or later.


OpenCVE Recommended Actions

  • Upgrade to Net::OAuth 0.32 or later.
  • Ensure all components that import Net::OAuth are using the updated version.
  • If an immediate upgrade is not possible, limit client requests that use problematic signature_method values and enforce stricter header or body size limits to constrain cache growth.

Generated by OpenCVE AI on August 17, 2026 at 18:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Vurtdev
Vurtdev net-oauth
Vendors & Products Vurtdev
Vurtdev net-oauth

Sun, 16 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
References

Sun, 16 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require. smart_require stores results in a process-global hash with no bound and no eviction, and keeps an entry for every class name it is asked about, including names that failed to load, because the return value of the failed eval is stored before the error is checked. The key comes off the wire on the server side: _signature_method_class builds the class name from the signature_method parameter of the incoming message, and verify resolves it before any signature is checked. A remote client chooses both how many entries are created and how long each key is. In a persistent server the hash grows for the life of the worker process until it exhausts memory. Header size limits bound the key length on the Authorization header path, but not on a POST body.
Title Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require
Weaknesses CWE-770
References

Subscriptions

Vurtdev Net-oauth
cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-08-17T16:21:57.584Z

Reserved: 2026-08-10T15:44:58.172Z

Link: CVE-2026-72888

cve-icon Vulnrichment

Updated: 2026-08-17T16:20:54.348Z

cve-icon NVD

Status : Deferred

Published: 2026-08-16T14:16:54.970

Modified: 2026-08-26T16:51:19.490

Link: CVE-2026-72888

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T19:00:05Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling