Crypt::SecretBuffer versions before 0.019 for Perl is suseceptible to timing attacks.
For example, if Crypt::SecretBuffer was used to store and compare plaintext passwords, then discrepencies in timing could be used to guess the secret password.
References
| Link | Resource |
|---|---|
| https://metacpan.org/release/NERDVANA/Crypt-SecretBuffer-0.019/source/Changes | Product Release Notes |
| http://www.openwall.com/lists/oss-security/2026/04/13/12 | Third Party Advisory Mailing List |
Configurations
History
06 May 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Nerdvana crypt\
Nerdvana |
|
| CPE | cpe:2.3:a:nerdvana:crypt\:\:secretbuffer:*:*:*:*:*:perl:*:* | |
| References | () https://metacpan.org/release/NERDVANA/Crypt-SecretBuffer-0.019/source/Changes - Product, Release Notes | |
| References | () http://www.openwall.com/lists/oss-security/2026/04/13/12 - Third Party Advisory, Mailing List |
15 Apr 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
14 Apr 2026, 02:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
13 Apr 2026, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-13 23:16
Updated : 2026-05-06 17:16
NVD link : CVE-2026-5086
Mitre link : CVE-2026-5086
CVE.ORG link : CVE-2026-5086
JSON object : View
Products Affected
nerdvana
- crypt\
CWE
CWE-208
Observable Timing Discrepancy
