Back to CVE List

CVE-2026-8647

Vulnerability Description

Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG module is available.

The random_bytes function fell back to using the built-in rand() function when none of the Perl modules Crypt::PRNG, Crypt::OpenSSL::Random, Net::SSLeay, Crypt::Random, or Bytes::Random::Secure were available.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-338
Source
NVD

External References

Discussion (0)

Add Comment

No comments yet. Be the first!