WWW::OAuth 1.000 and earlier for Perl uses the rand()...
High severity
Unreviewed
Published
Feb 13, 2026
to the GitHub Advisory Database
•
Updated Feb 17, 2026
Description
Published by the National Vulnerability Database
Feb 13, 2026
Published to the GitHub Advisory Database
Feb 13, 2026
Last updated
Feb 17, 2026
WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.
References