CVE-2026-6659

Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography.
Configurations

No configuration.

History

26 May 2026, 23:16

Type Values Removed Values Added
References
  • () https://github.com/ronsavage/Crypt-PasswdMD5/commit/a2f821637db0296082297aa4b02254ab08f0dc5e.patch -
  • () https://github.com/ronsavage/Crypt-PasswdMD5/pull/3 -
  • () https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.43/changes -

08 May 2026, 20:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/05/08/17 -

08 May 2026, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

08 May 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-08 18:16

Updated : 2026-05-26 23:16


NVD link : CVE-2026-6659

Mitre link : CVE-2026-6659

CVE.ORG link : CVE-2026-6659


JSON object : View

Products Affected

No product.

CWE
CWE-338

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)