CVE-2026-47372

EUVD-2026-31198
Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts.

These versions use the built-in rand function, which is predictable and unsuitable for cryptography.
PRNG
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 33.03%
Debian logo
Debian Releases
Debian Product
Codename
libcrypt-saltedhash-perl
bookworm
no-dsa
bullseye
postponed
forky
0.12-1
fixed
sid
0.12-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libcrypt-saltedhash-perl
bionic
Fixed 0.09-1ubuntu0.18.04.1~esm1
released
focal
Fixed 0.09-1ubuntu0.20.04.1~esm1
released
jammy
Fixed 0.09-1.1ubuntu0.1~esm1
released
noble
Fixed 0.09-3ubuntu0.24.04.1~esm1
released
questing
Fixed 0.09-3ubuntu0.25.10.1
released
resolute
Fixed 0.09-3ubuntu0.26.04.1~esm1
released