216.73.217.22

CVE-2026-11832

· Published 16/06/2026 00:16 · Modified 16/06/2026 17:16 · Author: The MITRE Corporation

Labels: CVE-2026-11832 2026-06-159b29abf9-4ab0-4765-b253-1875cd9b441eCVE-2026-11832CWE-338

Essential information

Published
16/06/2026 00:16
Modified
16/06/2026 17:16
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
9.1 CRITICAL (v3.1)
CISA KEV
No
CWE
CWE-338
EPSS (First)
P8.5% ?EPSS percentile: rank of this vulnerability versus all others. Higher percentile = more likely to be exploited. Learn more (score 0.00188)
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CVSS metrics

Description

Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was generated using an MD5 hash of the epoch time, which is predictable.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
9b29abf9-4ab0-4765-b253-1875cd9b441e
NVD
View on NVD

Affected products (CPE)

ProductCPE
dancer / dancer2 plugin auth oauth cpe:2.3:a:dancer:dancer2_plugin_auth_oauth:<0.22:*:*:*:*:*:*:*

References