Description
Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify.

verify resolves the signature method class from the signature_method parameter of the incoming message. signature_method is required on every request, so the algorithm used to check a signature is chosen by whoever sent it, and nothing lets the verifying party pin the method instead. When a message names HMAC-SHA1 or HMAC-SHA256, the key is derived from consumer_secret and token_secret rather than from the key the provider deployed.

A provider deployed on RSA-SHA1 holds only the consumer public key, and RFC 5849 does not use consumer_secret for that method, so the required parameter is filled with a placeholder. A client that names HMAC-SHA1 instead has its signature checked against that placeholder, so a guessable one is enough to forge requests for any consumer key and token.
Published: 2026-08-19
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in Net::OAuth versions before 0.33 allows an attacker to specify the signature algorithm in the signature_method parameter during OAuth request verification. Because the method is taken from the request and not constrained by the server, the verification code uses a placeholder key when HMAC‑SHA1 or HMAC‑SHA256 is chosen, even for a provider that is configured to use RSA‑SHA1. This causes the verifier to accept a forged signature created with a guessable key, effectively allowing the attacker to forge authenticated requests for any consumer key and token. The result is a complete bypass of OAuth authentication, providing attackers the ability to create or modify resources, read sensitive data, or abuse the service. This flaw is a CWE‑347 and CWE‑757 vulnerability.

Affected Systems

Any Perl application that imports the Net::OAuth CPAN module and validates OAuth requests using a version earlier than 0.33 is affected. The vulnerability is limited to the library; it does not require a particular web server or operating system, but any system that relies on Net::OAuth for OAuth verification without the patch is susceptible.

Risk and Exploitability

The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a relatively low likelihood of exploitation at present. Nevertheless, the impact of a successful exploit is high, as an attacker can forge authenticated requests with any consumer key and token. The attack vector is remote; an adversary only needs to send a crafted OAuth request over the network, and no special credentials or local code execution are required. The CVSS score is 9.8, confirming the high severity of this flaw.

Generated by OpenCVE AI on August 26, 2026 at 20:59 UTC.

Remediation

Vendor Solution

Upgrade to Net-OAuth 0.33 or later.


OpenCVE Recommended Actions

  • Upgrade to Net::OAuth version 0.33 or later.
  • Configure the application to reject OAuth requests that specify HMAC‑SHA1 or HMAC‑SHA256 unless explicitly allowed by the provider’s policy.
  • Validate that the key used for signature verification matches the stored RSA key for the provider and reject any request that fails this check.

Generated by OpenCVE AI on August 26, 2026 at 20:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Vurtdev
Vurtdev net-oauth
Vendors & Products Vurtdev
Vurtdev net-oauth

Wed, 19 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
References

Wed, 19 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Description Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify. verify resolves the signature method class from the signature_method parameter of the incoming message. signature_method is required on every request, so the algorithm used to check a signature is chosen by whoever sent it, and nothing lets the verifying party pin the method instead. When a message names HMAC-SHA1 or HMAC-SHA256, the key is derived from consumer_secret and token_secret rather than from the key the provider deployed. A provider deployed on RSA-SHA1 holds only the consumer public key, and RFC 5849 does not use consumer_secret for that method, so the required parameter is filled with a placeholder. A client that names HMAC-SHA1 instead has its signature checked against that placeholder, so a guessable one is enough to forge requests for any consumer key and token.
Title Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify
Weaknesses CWE-347
CWE-757
References

Subscriptions

Vurtdev Net-oauth
cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-08-26T18:03:05.016Z

Reserved: 2026-08-10T15:44:58.172Z

Link: CVE-2026-72889

cve-icon Vulnrichment

Updated: 2026-08-19T21:07:38.218Z

cve-icon NVD

Status : Deferred

Published: 2026-08-19T08:17:13.833

Modified: 2026-08-26T19:17:00.557

Link: CVE-2026-72889

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T21:00:12Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature

  • CWE-757

    Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')