๐Ÿ” CVE Alert

CVE-2026-75628

MEDIUM 5.7

Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_path accepts a backslash or tab in the return parameter

CVSS Score
5.7
EPSS Score
0.0%
EPSS Percentile
0th

Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_path accepts a backslash or tab in the return parameter. oauth2_login reads the return parameter from the initiation request, runs same_origin_path over it, and stores the survivor in the session flow record as the post-login redirect target. That check rejects a value that does not begin with a slash, one with a slash as its second byte, and one containing CR or LF. A backslash and a tab pass. The URL Standard treats a backslash as equivalent to a slash for special schemes, so `/\evil.example` parses with the authority `evil.example`. It also strips ASCII tab before parsing, so a tab between two leading slashes leaves `//evil.example`. A crafted link to the application's own login route lands the victim on the attacker's site after a genuine authentication. The redirect carries no authorization code or access token.

CWE CWE-601
Published Aug 20, 2026
Last Updated Aug 28, 2026
Stay Ahead of the Next One

Get instant alerts for

Be the first to know when new medium vulnerabilities are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
metacpan.org: https://metacpan.org/release/LNATION/Punk-OAuth2-0.03/changes metacpan.org: https://metacpan.org/release/LNATION/Punk-OAuth2-0.02/source/include/pox/pox_util.h#L94 datatracker.ietf.org: https://datatracker.ietf.org/doc/html/rfc9700#section-4.11.1 url.spec.whatwg.org: https://url.spec.whatwg.org/#relative-slash-state url.spec.whatwg.org: https://url.spec.whatwg.org/#concept-basic-url-parser openwall.com: http://www.openwall.com/lists/oss-security/2026/08/20/1