
Perl CPAN CVE-2026-12746: Dancer2::Plugin::Auth::OAuth::Provider before 0.23 do not support the OAuth 2.0 state parameter https://www.openwall.com/lists/oss-security/2026/07/04/9 CVE-2026-12740: Plack::Middleware::OAuth through 0.10 do not support the OAuth 2.0 state parameter https://www.openwall.com/lists/oss-security/2026/07/04/10
Post summary
The text discloses that Dancer2::Plugin::Auth::OAuth::Provider (<0.23) and Plack::Middleware::OAuth (≤0.10) lack OAuth 2.0 state parameter support, without specifying any exploit, patch, or active exploitation details.


