The random_bytes function fell back to using the built-in rand() function when none of the Perl modules Crypt::PRNG, Crypt::OpenSSL::Random, Net::SSLeay, Crypt::Random, or Bytes::Random::Secure were available.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to version 0.011 or later.
Vendor Workaround
Install one of the recommended Perl modules, such as Crypt::PRNG.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 28 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 27 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mik
Mik crypt::scryptkdf |
|
| Vendors & Products |
Mik
Mik crypt::scryptkdf |
Wed, 27 May 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 26 May 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG module is available. The random_bytes function fell back to using the built-in rand() function when none of the Perl modules Crypt::PRNG, Crypt::OpenSSL::Random, Net::SSLeay, Crypt::Random, or Bytes::Random::Secure were available. | |
| Title | Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG module is available | |
| Weaknesses | CWE-338 | |
| References |
|
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-05-28T14:09:56.026Z
Reserved: 2026-05-14T22:46:50.791Z
Link: CVE-2026-8647
Updated: 2026-05-27T01:41:36.078Z
Status : Deferred
Published: 2026-05-26T23:16:21.247
Modified: 2026-06-17T11:04:15.190
Link: CVE-2026-8647
No data.
OpenCVE Enrichment
Updated: 2026-05-28T18:45:24Z