CVE 7.5 HIGH

Apache::API::Password versions through v0.5.2 for Perl can generate insecure random values for salts_CVE-2026-5088

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

Apache::API::Password versions through v0.5.2 for Perl can generate insecure random values for salts.

The _make_salt and _make_salt_bcrypt methods will attept to load Crypt::URandom and then Bytes::Random::Secure to generate random bytes for the salt. If those modules are unavailable, it will simply return 16 bytes generated with Perl's built-in rand function.

The rand function is unsuitable for cryptographic use.

These salts are used for password hashing.

Basic Information

ID CVE-2026-5088
Source CPANSec
Published Apr 15, 2026 at 07:03
Modified Apr 16, 2026 at 12:05

Affected Product

Vendor JDEGUEST
Product Apache::API::Password
Affected Versions JDEGUEST Apache::API::Password 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.