External risk intelligence

Net::OAuth Signature Algorithm Selection Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-72889

This is a vulnerability in a library used to handle OAuth authentication. OAuth is a standard protocol commonly implemented in web applications, APIs, and services that are designed to be internet-facing to facilitate external authentication and authorization flows.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the Net::OAuth library for Perl, which is used in authentication processes. This issue allows for the potential manipulation of signature algorithms, which could lead to the forging of requests. The main concern is confirming relevance and exposure.

  • A library flaw lets sender pick authentication's signature method.
  • Critical flaw could allow forging requests for consumer data.
  • Confirm if your systems use this authentication library.

Attack Path

How an attacker could exploit the issue

An attacker can impersonate a legitimate user by manipulating the signature algorithm used in OAuth verification. This is possible because the vulnerable library allows the sender to specify the signature algorithm, and in certain configurations, the verification process relies on secrets that can be guessed, allowing an attacker to forge requests.

  • Network access required.
  • Sender specifies signature algorithm.
  • Forge any consumer key and token.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to forge authenticated requests to services that use Net::OAuth for signature verification. This is possible when the service improperly handles signature algorithms, allowing the sender to specify a method like HMAC-SHA1 or HMAC-SHA256, which can then be exploited using predictable secrets to bypass signature checks.

  • Forged requests could be sent.
  • An attacker could choose the signature algorithm.
  • Unauthorized actions could be performed.

Operational Fix

Recommended remediation, mitigation, and detection steps

Action for Net::OAuth vulnerability rests with the application teams integrating the library and the platform teams managing the underlying services. The first step is to identify all applications and services utilizing this library, assess their exposure and business criticality, and then assign ownership for remediation.

  • Application owners must confirm library usage.
  • Verify reachability and business impact.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Net::OAuth for Perl?

Net::OAuth is a software library designed for the Perl programming language. Developers integrate it into web applications and services to handle OAuth 1.0 authentication protocols, helping systems securely verify identity and authorize access between different services or APIs.

What does CVE-2026-72889 mean for signature verification?

This vulnerability, involving Improper Verification of Cryptographic Signature (CWE-347) and Selection of Less-Secure Algorithm (CWE-757), means the library lets the sender—rather than the application—choose the signature method. By forcing a specific method, an attacker can trick the system into using a weak or placeholder secret, allowing them to forge authenticated requests.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending a request to a service using the library and explicitly setting the 'signature_method' parameter to a HMAC algorithm. The bug occurs when the application relies on this user-provided value. If the application is not configured to force a specific, secure signature method, it defaults to the attacker's choice, bypassing intended cryptographic protections.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal flags this as likely relevant if your environment hosts internet-facing APIs or services that rely on OAuth for authentication. Because these services are designed to accept external requests, they are potential targets for attackers attempting to manipulate signature verification flows remotely.

What steps should I take if I use Net::OAuth?

First, conduct an inventory to identify all applications and internal services that include the Net::OAuth library. Once located, verify if these services currently allow the client to specify the signature algorithm. Finally, coordinate with your development teams to update the library to version 0.33 or higher, where signature method pinning is enforced.

References