CVE-2026-16615

EUVD-2026-47742
A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.
PRNG
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 16.85%
Debian logo
Debian Releases
Debian Product
Codename
librest
bookworm
vulnerable
bullseye
vulnerable
forky
vulnerable
sid
vulnerable
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
librest
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
librest-0_7-0
suse enterprise desktop 15 SP7
0.8.1-150600.4.3.1
fixed
suse enterprise sap 15 SP7
0.8.1-150600.4.3.1
fixed
suse enterprise server 15 SP4
0.8.1-150000.3.7.1
fixed
suse enterprise server 15 SP7
0.8.1-150600.4.3.1
fixed
suse enterprise workstation 15 SP7
0.8.1-150600.4.3.1
fixed
librest-1_0-0
suse enterprise desktop 15 SP7
0.9.1-150600.3.3.1
fixed
suse enterprise sap 15 SP7
0.9.1-150600.3.3.1
fixed
suse enterprise server 15 SP7
0.9.1-150600.3.3.1
fixed
librest-devel
suse enterprise desktop 15 SP7
0.9.1-150600.3.3.1
fixed
suse enterprise sap 12 SP5
0.8.0-13.3.1
fixed
suse enterprise sap 15 SP7
0.9.1-150600.3.3.1
fixed
suse enterprise server 12 SP5
0.8.0-13.3.1
fixed
suse enterprise server 15 SP4
0.8.1-150000.3.7.1
fixed
suse enterprise server 15 SP7
0.9.1-150600.3.3.1
fixed
librest0
suse enterprise sap 12 SP5
0.8.0-13.3.1
fixed
suse enterprise server 12 SP3
0.8.0-13.3.1
fixed
suse enterprise server 12 SP5
0.8.0-13.3.1
fixed
librest0-32bit
suse enterprise sap 12 SP5
0.8.0-13.3.1
fixed
suse enterprise server 12 SP3
0.8.0-13.3.1
fixed
suse enterprise server 12 SP5
0.8.0-13.3.1
fixed
librest0_7-devel
suse enterprise desktop 15 SP7
0.8.1-150600.4.3.1
fixed
suse enterprise sap 15 SP7
0.8.1-150600.4.3.1
fixed
suse enterprise server 15 SP7
0.8.1-150600.4.3.1
fixed
suse enterprise workstation 15 SP7
0.8.1-150600.4.3.1
fixed
typelib-1_0-Rest-0_7
suse enterprise desktop 15 SP7
0.8.1-150600.4.3.1
fixed
suse enterprise sap 15 SP7
0.8.1-150600.4.3.1
fixed
suse enterprise server 15 SP4
0.8.1-150000.3.7.1
fixed
suse enterprise server 15 SP7
0.8.1-150600.4.3.1
fixed
suse enterprise workstation 15 SP7
0.8.1-150600.4.3.1
fixed
typelib-1_0-Rest-1_0
suse enterprise desktop 15 SP7
0.9.1-150600.3.3.1
fixed
suse enterprise sap 15 SP7
0.9.1-150600.3.3.1
fixed
suse enterprise server 15 SP7
0.9.1-150600.3.3.1
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
rest
Azure Linux 3.0
0:0.9.0-2.azl3
fixed