These versions use the built-in rand function, which is predictable and unsuitable for cryptography.
No advisories yet.
Solution
Upgrade to version 0.261630 or later.
Workaround
No workaround given by the vendor.
Fri, 12 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arodland
Arodland crypt::pbkdf2 |
|
| Vendors & Products |
Arodland
Arodland crypt::pbkdf2 |
Fri, 12 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
cvssV3_1
|
Fri, 12 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography. | |
| Title | Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts | |
| Weaknesses | CWE-338 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-06-12T17:50:43.544Z
Reserved: 2026-05-26T18:28:03.845Z
Link: CVE-2026-9638
Updated: 2026-06-12T17:50:43.544Z
Status : Deferred
Published: 2026-06-12T16:16:34.937
Modified: 2026-06-12T18:16:36.030
Link: CVE-2026-9638
No data.
OpenCVE Enrichment
Updated: 2026-06-12T20:20:08Z