CVE 4.8 MEDIUM

Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG module is available_CVE-2026-8647

4.8 / 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

Description

Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG module is available.

The random_bytes function fell back to using the built-in rand() function when none of the Perl modules Crypt::PRNG, Crypt::OpenSSL::Random, Net::SSLeay, Crypt::Random, or Bytes::Random::Secure were available.

Basic Information

ID CVE-2026-8647
Source CPANSec
Published May 26, 2026 at 22:53
Modified May 28, 2026 at 14:09

Affected Product

Vendor MIK
Product Crypt::ScryptKDF
Affected Versions MIK Crypt::ScryptKDF 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.