Secrets were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to version 0.1.1 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 22 May 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tchatzi
Tchatzi authen::totp |
|
| Vendors & Products |
Tchatzi
Tchatzi authen::totp |
Thu, 21 May 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 21 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 21 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authen::TOTP versions before 0.1.1 for Perl generate secrets using rand. Secrets were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage. | |
| Title | Authen::TOTP versions before 0.1.1 for Perl generate secrets using rand | |
| Weaknesses | CWE-331 | |
| References |
|
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-05-21T21:31:45.691Z
Reserved: 2026-05-14T17:55:07.623Z
Link: CVE-2026-46473
Updated: 2026-05-21T21:31:45.691Z
Status : Deferred
Published: 2026-05-21T19:16:53.510
Modified: 2026-06-17T10:53:41.770
Link: CVE-2026-46473
No data.
OpenCVE Enrichment
Updated: 2026-05-22T12:38:31Z