CVE-2026-6659
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/05/2026
Last modified:
26/05/2026
Description
Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts.<br />
<br />
The built-in rand function is predictable, and unsuitable for cryptography.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/ronsavage/Crypt-PasswdMD5/commit/a2f821637db0296082297aa4b02254ab08f0dc5e.patch
- https://github.com/ronsavage/Crypt-PasswdMD5/pull/3
- https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.42/source/lib/Crypt/PasswdMD5.pm#L35-47
- https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.43/changes
- http://www.openwall.com/lists/oss-security/2026/05/08/17



