CVE-2026-11832: Biafra DANCER2::PLUGIN::AUTH::OAUTH

Critical severity, CVSS 9.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was generated using an MD5 hash of the epoch time, which is predictable.

Affected products

  • Biafra DANCER2::PLUGIN::AUTH::OAUTH: before 0.22 (fixed in 0.22)

Published 2026-06-15. Last modified 2026-06-17.