WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to WWW::OAuth 1.001 or higher
Workaround
No workaround given by the vendor.
References
History
Thu, 12 Feb 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. | |
| Title | WWW::OAuth 1.000 and earlier for Perl uses insecure rand() function for cryptographic functions | |
| Weaknesses | CWE-338 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-02-12T23:39:28.994Z
Reserved: 2025-04-16T09:05:34.360Z
Link: CVE-2025-40905
No data.
Status : Received
Published: 2026-02-13T00:16:03.280
Modified: 2026-02-13T00:16:03.280
Link: CVE-2025-40905
No data.
OpenCVE Enrichment
No data.
Weaknesses