oss-sec mailing list archives
CVE-2026-16235: Crypt::Password versions through 0.28 for Perl generate insecure random values for salts
From: Robert Rothenberg <rrwo () cpansec org>
Date: Mon, 20 Jul 2026 08:04:45 +0100
======================================================================== CVE-2026-16235 CPAN Security Group ======================================================================== CVE ID: CVE-2026-16235 Distribution: Crypt-Password Versions: through 0.28 MetaCPAN: https://metacpan.org/dist/Crypt-Password Crypt::Password versions through 0.28 for Perl generate insecure random values for salts Description ----------- Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography. Problem types ------------- - CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) Workarounds ----------- Users can generate a salt manually using a module such as Crypt::URandom::Token, and pass the salt directly to the password and crypt_password methods. This module has not been updated since 2012. Users should migrate to an alternative solution. References ---------- https://metacpan.org/release/DRSTEVE/Crypt-Password-0.28/source/lib/Crypt/Password.pm#L306-309
Current thread:
- CVE-2026-16235: Crypt::Password versions through 0.28 for Perl generate insecure random values for salts Robert Rothenberg (Jul 20)
