- Package:
- src:libnet-oauth-perl
- Source:
- src:libnet-oauth-perl
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-08-19 15:51:01 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for libnet-oauth-perl. CVE-2026-72889[0]: | Net::OAuth versions before 0.33 for Perl allow the sender to choose | the signature algorithm in verify. verify resolves the signature | method class from the signature_method parameter of the incoming | message. signature_method is required on every request, so the | algorithm used to check a signature is chosen by whoever sent it, | and nothing lets the verifying party pin the method instead. When a | message names HMAC-SHA1 or HMAC-SHA256, the key is derived from | consumer_secret and token_secret rather than from the key the | provider deployed. A provider deployed on RSA-SHA1 holds only the | consumer public key, and RFC 5849 does not use consumer_secret for | that method, so the required parameter is filled with a placeholder. | A client that names HMAC-SHA1 instead has its signature checked | against that placeholder, so a guessable one is enough to forge | requests for any consumer key and token. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-72889 https://www.cve.org/CVERecord?id=CVE-2026-72889 [1] https://lists.security.metacpan.org/cve-announce/msg/42818761/ [2] https://github.com/vurtdev/Net-OAuth/security/advisories/GHSA-c8rm-g5cm-4pf5 [3] https://github.com/vurtdev/Net-OAuth/commit/c467adf45c8d77ac4b92ad78b3eebf949252ba7f Please adjust the affected versions in the BTS as needed. Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
libnet-oauth-perl, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1144854@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
gregor herrmann <gregoa@debian.org> (supplier of updated libnet-oauth-perl package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 19 Aug 2026 17:31:51 +0200
Source: libnet-oauth-perl
Architecture: source
Version: 0.33-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Perl Group <pkg-perl-maintainers@lists.alioth.debian.org>
Changed-By: gregor herrmann <gregoa@debian.org>
Closes: 1144854 1144855
Changes:
libnet-oauth-perl (0.33-1) unstable; urgency=medium
.
* Import upstream version 0.33.
- Restrict the verification algorithm to those specified in the
allowed_signature_methods, which is now required. This is a breaking
change. (CVE-2026-72889)
(Closes: #1144854)
- HMAC_SHA1, HMAC_SHA256 and PLAINTEXT signature verification now use
constant-time comparison (CVE-2026-75589).
(Closes: #1144855)
- HMAC_SHA1 and HMAC_SHA256 signature keys cannot be blank.
* Add note about breaking change to debian/NEWS.Developer.
* debian/libnet-oauth-perl.docs: CONTRIBUTING.md is gone.
* Update years of upstream copyright.
* Update debian/upstream/metadata.
Checksums-Sha1:
50b23c88eb0c90750dbe55e32619b8bb7292b5d6 2646 libnet-oauth-perl_0.33-1.dsc
5ca659ca319b12642b6a3480a054034466148953 32999 libnet-oauth-perl_0.33.orig.tar.gz
e1f16bdbc85ee6edc5f0b0b15d83bbfa88276f8c 4764 libnet-oauth-perl_0.33-1.debian.tar.xz
1afa6e1be7289f4c1421f35994149c13c82521e4 117684 libnet-oauth-perl_0.33-1.git.tar.xz
cdf0d8e7fb4e1add01835e47aceabaf38625fc7c 17588 libnet-oauth-perl_0.33-1_source.buildinfo
Checksums-Sha256:
35063d97fb952ebd935fe8a3b006499f3a731cde1b97bf21a8b6d95778a12fd6 2646 libnet-oauth-perl_0.33-1.dsc
06a290c13bc1c9c2acee33a79089b32f3047964925d4ea992eb6c1cc3d8df6c1 32999 libnet-oauth-perl_0.33.orig.tar.gz
c7c2c5d2e64af09fa5a6e886547f1c186daa2fa72b474d676981cead0baf1b58 4764 libnet-oauth-perl_0.33-1.debian.tar.xz
05b604e7a91ebcf723780edd2237d4a9c77cc2a59a232f3df066cbdb47d1ccaf 117684 libnet-oauth-perl_0.33-1.git.tar.xz
9740064e55fa9be08122c3914548848e614ec28684e5ab2f7572828add605ebe 17588 libnet-oauth-perl_0.33-1_source.buildinfo
Files:
d6387dcaa1107ee2810a4971deaa59a0 2646 perl optional libnet-oauth-perl_0.33-1.dsc
d408c711991fdda9235b5de10e0bb3d8 32999 perl optional libnet-oauth-perl_0.33.orig.tar.gz
8e93e596abffb38efac651808cb648a6 4764 perl optional libnet-oauth-perl_0.33-1.debian.tar.xz
301692c391a0c93eb598a9f72deaa0c9 117684 perl None libnet-oauth-perl_0.33-1.git.tar.xz
0e1a9fe0207e4399cbf20f798063875a 17588 perl optional libnet-oauth-perl_0.33-1_source.buildinfo
Git-Tag-Info: tag=abf893256b4d71cf0880e6fa7c87cd7add15a58a fp=d1e1316e93a760a8104d85fabb3a68018649aa06
Git-Tag-Tagger: gregor herrmann <gregoa@debian.org>
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmqFzT4ACgkQYG0ITkaD
wHkm3hAAr0FfKW70u0eQLGrQdNpNufCMRCdlNyDal2g+xSxB6Ri6rLGO1AN7cy3h
r0DOQhNHJyhUU4R54uiC8fzE/hNsiXobLbZ7Oq2hVB1JmQDDV35KpYj7m92hjRE0
iupvriIIhf6zzt/igZpVaNNX25jQOagAQcgIqERfjUACTMZhttWcb5yzI6t5ofwQ
+bk/jCtcwoA5JQs362nO85SrVcUi0y030nFfvjIgNML/itZVnJigfaYBFpw6e+Hn
YYIWkY62E7tzUq6LKuJ45X1wImV3jEejOaGno1SLtK4190VlXBhdsc57FboMCyQN
T7BviRhQz9Cj5xCrYsfcR/1fem1nNiTt1tDq2uEIk55gvJJ1CNJZfarah09tR4+D
vtQmIByYXbtfPKPbynkEvmB5ODQ/6zf8oUphwWXBQlMx2R0Sox4WQvdKWi6uE04X
B1v8MvwzQ1f3/5+4NfwauuIIVN+/OqVhl1IoQ9R9aIh5hm7MzQe4+Soz/eJ2lQGE
h1QGItZjXTZfJUE43s6z8Sy/TOmR7+Yi6l2XUvaO2IplbP+hyXnEox7jf8/b5RzP
ApqwZuajEvMEFw4VpqjdM+MzkO9S3/SvVAwBWjqp7RqxAF3gbtgcY/LRJZFk3vrA
2H2hOwQrmh5LrJgExhJapQrq+wB5WEmKOSpZMUNp1AlIl3ahbUE=
=9xmW
-----END PGP SIGNATURE-----