{"id":"CVE-2026-13410","summary":"Dancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verification disabled","details":"Dancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verification disabled.\n\nThe default user agent is initialised with SSL_verify_mode explicitly disabled.\n\nAn attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token exchange and userinfo fetch, return a forged access_token and user profile, and be logged in to the Dancer application as any Google user.","modified":"2026-08-13T04:02:20.723562174Z","published":"2026-07-17T12:50:30.389Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/13xxx/CVE-2026-13410.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"fixed":"0.08"}]},{"source":"DESCRIPTION","extracted_events":[{"fixed":"0.08"}]}],"cna_assigner":"CPANSec","cwe_ids":["CWE-295"]},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/07/17/8"},{"type":"WEB","url":"https://cpan.org/modules"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/13xxx/CVE-2026-13410.json"},{"type":"ADVISORY","url":"https://metacpan.org/release/GARU/Dancer-Plugin-Auth-Google-0.08/changes"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-13410"},{"type":"REPORT","url":"https://github.com/garu/Dancer-Plugin-Auth-Google/pull/5"},{"type":"FIX","url":"https://github.com/garu/Dancer-Plugin-Auth-Google/commit/2fdb72527eaa0e11a5c134c597f1e44e37411d95.patch"},{"type":"FIX","url":"https://security.metacpan.org/patches/D/Dancer-Plugin-Auth-Google/0.07/CVE-2026-13410-r1.patch"},{"type":"PACKAGE","url":"https://github.com/garu/Dancer-Plugin-Auth-Google"},{"type":"ARTICLE","url":"https://metacpan.org/pod/Furl#HTTPS-requests-claims-warnings!"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/garu/dancer-plugin-auth-google","events":[{"introduced":"0"},{"fixed":"2fdb72527eaa0e11a5c134c597f1e44e37411d95"}],"database_specific":{"source":"REFERENCES"}}],"versions":["0.06","0.03","0.02","0.01"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-13410.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L"}]}