
Perl CPAN CVE-2026-9733: Mojolicious::Plugin::Web::Auth::OAuth2 through 0.17 for Perl have an insecure default state parameter https://www.openwall.com/lists/oss-security/2026/06/23/1 CVE-2026-11373: Net::Statsite::Client through 1.1.0 allow metric injections https://www.openwall.com/lists/oss-security/2026/06/22/4
Post summary
The text announces and describes two Perl CPAN package vulnerabilities, providing technical details about the weaknesses but no evidence of PoC, exploitation, patches, or false claims.



