
Open Source Security mailing list@oss_security
Disclosure
Perl CPAN CVE-2026-13089: OIDC::Lite through 0.12.1 allow ID Token signature verification bypass via a token-controlled algorithm allowlist https://www.openwall.com/lists/oss-security/2026/07/22/17 CVE-2026-16634: TOML::XS before 0.06 bundle an unsupported and vulnerable version of tomlc99 https://www.openwall.com/lists/oss-security/2026/07/24/4
Post summary
The excerpt announces two Perl CPAN package vulnerabilities: OIDC::Lite’s ID Token verification bypass and TOML::XS’s bundling of a vulnerable tomlc99.
00000181
4.7K followersView on X
