Description
Net::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG.

The MSE (Message Stream Encryption) handshake derives its 160-bit Diffie-Hellman private key from Perl's rand(), a non-cryptographic drand48-class generator seeded once per process, in KeyExchange.pm. The shared secret and the RC4 keys derived from it (the SHA-1 of "keyA" or "keyB", the shared secret, and the infohash) therefore depend entirely on a predictable PRNG. The same handshake sends, in cleartext, random padding drawn from the same rand() sequence in _random_pad, immediately after the public key and the private-key draw.

A passive observer of the handshake recovers the PRNG state from the cleartext padding, reconstructs the private key, computes the shared secret from the peer's public key on the wire, derives the RC4 keys, and decrypts the connection, defeating the passive-observation obfuscation MSE provides.
Published: 2026-06-30
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Net::BitTorrent versions before 2.1.0 generate the 160‑bit Diffie‑Hellman private key for the Message Stream Encryption (MSE) handshake by calling Perl's non‑cryptographic rand(). This drand48‑class generator is seeded once per process in KeyExchange.pm, making its output fully predictable. The shared secret and the RC4 keys derived from it (the SHA‑1 of "keyA" or "keyB", the shared secret, and the infohash) therefore depend entirely on this predictable PRNG. The same handshake also sends, in cleartext, random padding drawn from the same rand() sequence in _random_pad, immediately after the public key and private‑key draw. A passive observer of the handshake can recover the PRNG state from this cleartext padding, reconstruct the private key, compute the shared secret from the peer’s public key on the wire, derive the RC4 keys, and decrypt the entire session, thereby defeating MSE’s confidentiality guarantee.

Affected Systems

SANKO Net::BitTorrent library for all Perl releases earlier than version 2.1.0. Every installation that loads these affected versions and uses MSE encryption for peer connections is vulnerable. The vulnerability stems from the use of Perl’s rand() for key generation and padding as described.

Risk and Exploitability

The CVSS score of 5.9 indicates a medium severity impact. An EPSS score of less than 1% reflects a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only passive observation of the MSE handshake; no privileged access or active manipulation is needed. Once the PRNG state is recovered from the clear‑text padding, the attacker can reconstruct the Diffie‑Hellman private key, compute the shared secret, derive the RC4 keys, and decrypt the session, fully compromising confidentiality.

Generated by OpenCVE AI on July 31, 2026 at 16:37 UTC.

Remediation

Vendor Solution

Upgrade to version 2.1.0 or later.


OpenCVE Recommended Actions

  • Upgrade Net::BitTorrent to version 2.1.0 or later on all systems that use the library.
  • If an immediate upgrade cannot be performed, reconfigure the application to disable MSE encryption or replace it with a protocol that uses a cryptographic PRNG for key generation.
  • Apply network segmentation or implement an additional TLS layer so that passive observers cannot see the MSE handshake, reducing the window for key recovery.

Generated by OpenCVE AI on July 31, 2026 at 16:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 20 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Description Net::BitTorrent versions through 2.0.1 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG. The MSE (Message Stream Encryption) handshake derives its 160-bit Diffie-Hellman private key from Perl's rand(), a non-cryptographic drand48-class generator seeded once per process, in KeyExchange.pm. The shared secret and the RC4 keys derived from it (the SHA-1 of "keyA" or "keyB", the shared secret, and the infohash) therefore depend entirely on a predictable PRNG. The same handshake sends, in cleartext, random padding drawn from the same rand() sequence in _random_pad, immediately after the public key and the private-key draw. A passive observer of the handshake recovers the PRNG state from the cleartext padding, reconstructs the private key, computes the shared secret from the peer's public key on the wire, derives the RC4 keys, and decrypts the connection, defeating the passive-observation obfuscation MSE provides. Net::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG. The MSE (Message Stream Encryption) handshake derives its 160-bit Diffie-Hellman private key from Perl's rand(), a non-cryptographic drand48-class generator seeded once per process, in KeyExchange.pm. The shared secret and the RC4 keys derived from it (the SHA-1 of "keyA" or "keyB", the shared secret, and the infohash) therefore depend entirely on a predictable PRNG. The same handshake sends, in cleartext, random padding drawn from the same rand() sequence in _random_pad, immediately after the public key and the private-key draw. A passive observer of the handshake recovers the PRNG state from the cleartext padding, reconstructs the private key, computes the shared secret from the peer's public key on the wire, derives the RC4 keys, and decrypts the connection, defeating the passive-observation obfuscation MSE provides.
Title Net::BitTorrent versions through 2.0.1 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG Net::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG
References

Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Sanko
Sanko net::bittorrent
Vendors & Products Sanko
Sanko net::bittorrent

Tue, 30 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 11:45:00 +0000

Type Values Removed Values Added
Description Net::BitTorrent versions through 2.0.1 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG. The MSE (Message Stream Encryption) handshake derives its 160-bit Diffie-Hellman private key from Perl's rand(), a non-cryptographic drand48-class generator seeded once per process, in KeyExchange.pm. The shared secret and the RC4 keys derived from it (the SHA-1 of "keyA" or "keyB", the shared secret, and the infohash) therefore depend entirely on a predictable PRNG. The same handshake sends, in cleartext, random padding drawn from the same rand() sequence in _random_pad, immediately after the public key and the private-key draw. A passive observer of the handshake recovers the PRNG state from the cleartext padding, reconstructs the private key, computes the shared secret from the peer's public key on the wire, derives the RC4 keys, and decrypts the connection, defeating the passive-observation obfuscation MSE provides.
Title Net::BitTorrent versions through 2.0.1 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG
Weaknesses CWE-330
CWE-338
References

Subscriptions

Sanko Net::bittorrent
cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-07-20T06:43:12.712Z

Reserved: 2026-06-23T18:20:33.514Z

Link: CVE-2026-57082

cve-icon Vulnrichment

Updated: 2026-06-30T14:19:42.344Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T16:45:03Z

Weaknesses
  • CWE-330

    Use of Insufficiently Random Values

  • CWE-338

    Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)