WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Feb 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. | |
| Title | WWW::OAuth 1.000 and earlier for Perl uses insecure rand() function for cryptographic functions | |
| Weaknesses | CWE-338 | |
| References |
|
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-02-12T23:39:28.994Z
Reserved: 2025-04-16T09:05:34.360Z
Link: CVE-2025-40905
No data.
Status : Awaiting Analysis
Published: 2026-02-13T00:16:03.280
Modified: 2026-02-13T14:23:48.007
Link: CVE-2025-40905
No data.
OpenCVE Enrichment
No data.