9.1
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Description
Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts.
These versions use the built-in rand function, which is predictable and unsuitable for cryptography.
These versions use the built-in rand function, which is predictable and unsuitable for cryptography.
AI Analysis
Insecure random value generation for salts in Crypt::SaltedHash versions through 0.09
Basic Information
ID
CVE-2026-47372
Source
CPANSec
Published
May 20, 2026 at 22:08
Modified
May 21, 2026 at 14:12
Affected Product
Vendor
RRWO
Product
Crypt::SaltedHash
Version
0.09
Affected Versions
RRWO Crypt::SaltedHash 0
CWE Classification
AI Assessment
AI Score
9.1 / 10
AI Severity
Critical
Vendor
RRWO
Product
Crypt::SaltedHash
Version
0.09