# CVE-2026-9733

## Summary

- **CVE ID:** CVE-2026-9733
- **Severity:** CRITICAL
- **CVSS Score:** 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
- **CWE:** CWE-340, CWE-338
- **Published:** Jun 23, 2026
- **Last Modified:** Jun 23, 2026

## Description

Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter.

When no state generator is specified in the constructor, the module defaults to using a SHA-1 hash of predictable and low-entropy sources, including the epoch time (which is leaked via the HTTP Date header) and a call to Perl's built-in rand function.

A predictable state allows an attacker to hijack another user's session through cross site request forgery (CSRF).

## Affected Products

- HAYAJO — Mojolicious::Plugin::Web::Auth::OAuth2 (0)

## References

- [CNA](https://metacpan.org/release/HAYAJO/Mojolicious-Plugin-Web-Auth-0.17/source/lib/Mojolicious/Plugin/Web/Auth/OAuth2.pm#L129-131)
- [CNA](https://datatracker.ietf.org/doc/html/rfc6749#section-10.12)
- [CNA](https://security.metacpan.org/patches/M/Mojolicious-Plugin-Web-Auth/0.17/CVE-2026-9733-r2.patch)
- [CVE](http://www.openwall.com/lists/oss-security/2026/06/23/1)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.52%
- **EPSS Percentile:** 42.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._