A security flaw tracked as CVE-2026-66901 affects Google::Auth for Perl versions before 0.09, allowing server-side request forgery (SSRF) and credential exfiltration when applications build credentials from untrusted or partially trusted JSON configuration. The issue stems from unvalidated URLs embedded in credential data, which can cause affected applications to send outbound requests to attacker-controlled hosts, including internal services and link-local metadata endpoints, while transmitting sensitive authentication material.
The vulnerability impacts multiple credential flows, including external_account, authorized_user, impersonated_service_account, and service_account. Google’s Perl auth library repository shows a related remediation in a security fix titled "Validate token_uri in ServiceAccountCredentials", and version 0.09 is reported to fully address the issue by validating URL hosts against googleapis.com or an application-pinned universe domain before requests are made; versions 0.06 through 0.08 only provided partial mitigations.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Robert Rothenberg of the CPAN Security Group published an advisory for CVE-2026-66901 describing SSRF and credential exfiltration risks in Google::Auth versions before 0.09 affecting multiple credential flows.
Version 0.09 added URL validation to ServiceAccountCredentials and fully fixed the SSRF and credential exfiltration issue by validating URL hosts against googleapis.com or an application-pinned universe domain before requests are made.
A security-related repository commit titled "fix(security): Validate token_uri in ServiceAccountCredentials" was dated August 3, 2026, indicating remediation work in the Google-Auth component for service account credential handling.
Version 0.08 moved _validate_url to Google::Auth::Credentials and added URL validation to UserRefreshCredentials and ImpersonatedServiceAccountCredentials, extending but not fully completing the fix.
Version 0.06 introduced a partial mitigation by adding a _validate_url host check to the external_account class, but the check relied on a universe_domain value read from the same credentials JSON.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.