The default user agent is initialised with SSL_verify_mode explicitly disabled.
An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token exchange and userinfo fetch, return a forged access_token and user profile, and be logged in to the Dancer application as any Google user.
No advisories yet.
Solution
Upgrade to version 0.08 or later.
Workaround
For versions 0.07 or earlier, there is no caller-side override. Apply the patch.
Tue, 11 Aug 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled. The default user agent is initialised with SSL_verify_mode explicitly disabled. An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token exchange and userinfo fetch, return a forged access_token and user profile, and be logged in to the Dancer application as any Google user. | Dancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verification disabled. The default user agent is initialised with SSL_verify_mode explicitly disabled. An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token exchange and userinfo fetch, return a forged access_token and user profile, and be logged in to the Dancer application as any Google user. |
| Title | Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled | Dancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verification disabled |
| References |
|
Thu, 23 Jul 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Garu
Garu dancer::plugin::auth::google |
|
| Vendors & Products |
Garu
Garu dancer::plugin::auth::google |
Fri, 17 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 17 Jul 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled. The default user agent is initialised with SSL_verify_mode explicitly disabled. An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token exchange and userinfo fetch, return a forged access_token and user profile, and be logged in to the Dancer application as any Google user. | |
| Title | Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled | |
| Weaknesses | CWE-295 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-08-11T18:02:06.250Z
Reserved: 2026-06-26T10:06:50.040Z
Link: CVE-2026-13410
Updated: 2026-07-17T15:28:12.202Z
Status : Deferred
Published: 2026-07-17T13:17:56.663
Modified: 2026-08-11T18:17:19.290
Link: CVE-2026-13410
No data.
OpenCVE Enrichment
Updated: 2026-07-31T00:30:18Z