Trog::TOTP versions before 1.006 for Perl generate secrets using rand.
Secrets were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage.
Secrets were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to version 1.006 or later.
Workaround
No workaround given by the vendor.
References
History
Fri, 15 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Trog::TOTP versions before 1.006 for Perl generate secrets using rand. Secrets were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage. | |
| Title | Trog::TOTP versions before 1.006 for Perl generate secrets using rand | |
| Weaknesses | CWE-331 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-05-15T17:41:32.229Z
Reserved: 2026-05-14T17:55:07.623Z
Link: CVE-2026-46474
No data.
Status : Received
Published: 2026-05-15T18:16:26.053
Modified: 2026-05-15T18:16:26.053
Link: CVE-2026-46474
No data.
OpenCVE Enrichment
Updated: 2026-05-15T19:30:05Z
Weaknesses