CVE-2025-40905

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/02/2026
Last modified:
10/03/2026

Description

WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dbook:www\:\:oauth:*:*:*:*:*:perl:*:* 1.000 (including)