DFIR Lab[verified]@DFIR_LabDisclosure
The post announces CVE‑2026‑12740, highlighting a login‑CSRF flaw in Plack::Middleware::OAuth due to missing OAuth 2.0 state support, but it provides no PoC, exploit code, or active exploitation details.
Open Source Security mailing list@oss_securityDisclosure
This post announces two new CVEs affecting Perl modules that lack OAuth 2.0 state parameter support; no PoC, exploit, patch, or active exploitation details are provided.
VulDB 🛡@vuldbActive Exploitation
The brief notice indicates that attackers are actively targeting CVE-2026-12740, but provides no proof of concept, exploit code, technical details, or patch information.
Infoflowcloud@infoflowcloudDisclosure
The post announces CVE-2026-12740, providing a technical detail about missing OAuth 2.0 state support, but offers no PoC, exploit, patch, or evidence of active exploitation.
CVE@CVEnewDisclosure
The post announces CVE‑2026‑12740, noting that Plack::Middleware::OAuth up to 0.10 lacks OAuth 2.0 state parameter support, but offers no exploitation, patch, or PoC details.