A new vulnerability in Punk OAuth2 for Perl allows attackers to redirect users to an external website immediately after they successfully log in. The issue, documented as CVE-2026-75628 , concerns the return parameter checking and was fixed in version 0.03.

The vulnerability does not in itself allow the theft of passwords or authorization codes. However, it creates a credible deception path: the user initiates the login from the correct application, completes authentication, and is then redirected to an address controlled by the attacker.
See also: OAuth phishing attacks are evolving
Punk OAuth2: the return parameter vulnerability
Punk OAuth2 uses the oauth2_login to read the return from the login request. The value is passed through same_origin_path, which stores the destination in the session flow so that the user can return to the home page after authentication.
The check rejected addresses that did not start with a slash, addresses with a second slash, and line break characters. It did not, however, exclude backslashes or horizontal tabs. Browsers treat backslashes as slashes in special URL schemes and strip tabs before parsing the address.
Thus, a link to the legitimate login page could contain a specially crafted value, such as /\\evil.example. After authentication was complete, the address could be parsed as an external destination. The official CVE log clarifies that the redirect does not transfer an authorization code or access token to the third-party site.

What CVE-2026-75628 means for applications
The vulnerability primarily affects applications that use Punk OAuth2 and accept the return without an additional whitelist policy. For the attack to succeed, the user must follow the specially crafted link and complete the login normally. The result looks like a legitimate transition, which can empower a subsequent phishing attempt.
CVE logging does not assign a CVSS score and does not report public exploit code. This does not mean that the vulnerability should be ignored. Post-login redirects often act as a link in social engineering chains, especially when the application is used by multiple organizations or when users are accustomed to trusting the original domain.
The peculiarity lies in the gap between the grammar of a URL and its final interpretation by the browser. A check that only sees the first bytes may consider a path safe, while the URL parser later converts the characters into a different structure. For this reason, checks must be done with a reliable library and follow the same specification as the client.
In single sign-on environments, the issue requires additional attention. A user redirected to a page with a similar appearance could retype information or install malicious content. The application should maintain a clear policy on where re-entry is allowed and reject any external origin.
See also: Grav API plugin: vulnerability and leakage of JWT tokens via URL
The patched version of Punk OAuth2
The maintainers fixed the issue in version 0.03, which was released on August 18, 2026. According to the release notes, the change rejects all C0 control characters and the DEL character, while excluding backslashes anywhere in the path.

Administrators should immediately upgrade any Punk OAuth2 that are on a version prior to 0.03 and review any custom URL validation functions. In addition, it is preferable for applications to use predefined internal destinations rather than trusting arbitrary values from user requests.
Until the upgrade is complete, a temporary rule can be implemented that rejects any value with a backslash, control character, or double leading slash. The measure is not a replacement for the official fix, as different libraries may normalize addresses differently. However, it is a useful limitation for applications that cannot be upgraded immediately.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The SecNews technical team also recommends checking the log files for unusual return, such as values with backslashes, tabs, or double leading slashes. The search does not in itself prove a successful attack, but it can help identify links that need further investigation.
See also: WordPress: backdoor in page redirect plugin

CVE -2026-75628 is an example of why address validation should follow how browsers actually interpret them, not just a simple character comparison. Upgrading to Punk OAuth2 0.03 and limiting allowed destinations significantly reduces the risk.
