CVE-2026-9733: Hayajo mojolicious::plugin::web::auth::oauth2
Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.
Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no state generator is specified in the constructor, the module defaults to using a SHA-1 hash of predictable and low-entropy sources, including the epoch time (which is leaked via the HTTP Date header) and a call to Perl's built-in rand function. A predictable state allows an attacker to hijack another user's session through cross site request forgery (CSRF).
Affected products
- Hayajo mojolicious::plugin::web::auth::oauth2: up to and including 0.17
Published 2026-06-23. Last modified 2026-06-23.