CVE-2026-5086
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/04/2026
Last modified:
06/05/2026
Description
Crypt::SecretBuffer versions before 0.019 for Perl is suseceptible to timing attacks.<br />
<br />
For example, if Crypt::SecretBuffer was used to store and compare plaintext passwords, then discrepencies in timing could be used to guess the secret password.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:nerdvana:crypt\:\:secretbuffer:*:*:*:*:*:perl:*:* | 0.019 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



