7.3
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Description
WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.
Basic Information
ID
CVE-2025-40905
Source
CPANSec
Published
Feb 12, 2026 at 23:39
Modified
Feb 17, 2026 at 15:05
Affected Product
Vendor
DBOOK
Product
WWW::OAuth
Affected Versions
DBOOK WWW::OAuth 0