Description
Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require.

smart_require stores results in a process-global hash with no bound and no eviction, and keeps an entry for every class name it is asked about, including names that failed to load, because the return value of the failed eval is stored before the error is checked. The key comes off the wire on the server side: _signature_method_class builds the class name from the signature_method parameter of the incoming message, and verify resolves it before any signature is checked.

A remote client chooses both how many entries are created and how long each key is. In a persistent server the hash grows for the life of the worker process until it exhausts memory. Header size limits bound the key length on the Authorization header path, but not on a POST body.
Published: 2026-08-16
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is found in Net::OAuth versions prior to 0.32 for Perl. The smart_require routine stores the result of module load operations in a global hash without imposing any size limit or eviction policy, even when the load fails. Because the cache key is derived from the signature_method parameter supplied by an OAuth client, an attacker can trigger repeated failed loads of arbitrary class names. Each failed attempt reserves space in the hash, eventually exhausting the process memory and causing a denial of service.

Affected Systems

Perl applications that rely on Net::OAuth 0.30 or earlier to process OAuth requests, such as web services, APIs, or any server component that interprets the signature_method field from client messages. The issue is triggered when the server creates a class name from client data and attempts to load it; any application using the vulnerable library is at risk.

Risk and Exploitability

The flaw can be triggered remotely by any client able to send OAuth messages. By controlling the signature_method value and optionally the size of fields in the Authorization header or POST body, the attacker can determine the number and length of cache entries. Although there is no reported EPSS or CVSS score, the unbounded memory growth presents a high likelihood of causing service interruption for long‑running workers. The vulnerability is not yet listed in the CISA KEV catalog, but the lack of bounds makes it a significant denial‑of‑service risk.

Generated by OpenCVE AI on August 16, 2026 at 15:20 UTC.

Remediation

Vendor Solution

Upgrade to Net-OAuth 0.32 or later.


OpenCVE Recommended Actions

  • Upgrade to Net::OAuth 0.32 or later.
  • Ensure all components that import Net::OAuth are using the updated version.
  • If an immediate upgrade is not possible, limit client requests that use problematic signature_method values and enforce stricter header or body size limits to constrain cache growth.

Generated by OpenCVE AI on August 16, 2026 at 15:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 16 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
References

Sun, 16 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require. smart_require stores results in a process-global hash with no bound and no eviction, and keeps an entry for every class name it is asked about, including names that failed to load, because the return value of the failed eval is stored before the error is checked. The key comes off the wire on the server side: _signature_method_class builds the class name from the signature_method parameter of the incoming message, and verify resolves it before any signature is checked. A remote client chooses both how many entries are created and how long each key is. In a persistent server the hash grows for the life of the worker process until it exhausts memory. Header size limits bound the key length on the Authorization header path, but not on a POST body.
Title Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require
Weaknesses CWE-770
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-08-16T17:06:06.006Z

Reserved: 2026-08-10T15:44:58.172Z

Link: CVE-2026-72888

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-16T14:16:54.970

Modified: 2026-08-16T17:17:41.670

Link: CVE-2026-72888

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-16T15:30:04Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling