
CVE-2026-75589 Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify. Each of the three compa… https://www.cve.org/CVERecord?id=CVE-2026-75589
Post summary
The statement outlines CVE‑2026‑75589, detailing a timing‑attack vulnerability in Net::OAuth’s signature verification logic for Perl implementations.

