CVE-2026-11702
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/06/2026
Last modified:
01/07/2026
Description
Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes.<br />
<br />
When an object is initialised before forking, then the internal state for the PRNG is shared across processes and identical random streams will be produced.<br />
<br />
Secrets generated in multiprocess applications are predictable across processes.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/daoswald/Bytes-Random-Secure-Tiny/issues/6
- https://github.com/daoswald/Bytes-Random-Secure-Tiny/pull/7
- https://security.metacpan.org/patches/B/Bytes-Random-Secure-Tiny/1.011/CVE-2026-11702-r1.patch
- https://www.cve.org/CVERecord?id=CVE-2026-11625
- https://www.cve.org/CVERecord?id=CVE-2026-41564



