https://lists.security.metacpan.org/cve-announce/msg/36977848/ warns:
========================================================================
CVE-2025-40905                                       CPAN Security Group
========================================================================

         CVE ID:  CVE-2025-40905
   Distribution:  WWW-OAuth
       Versions:  through 1.000

       MetaCPAN:  https://metacpan.org/dist/WWW-OAuth

WWW::OAuth 1.000 and earlier for Perl uses insecure rand() function for
cryptographic functions

Description
-----------
WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the
default source of entropy, which is not cryptographically secure, for
cryptographic functions.

Problem types
-------------
- CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator
   (PRNG)

Solutions
---------
Upgrade to WWW::OAuth 1.001 or higher

References
----------
https://perldoc.perl.org/functions/rand
https://security.metacpan.org/docs/guides/random-data-for-security.html
https://metacpan.org/release/DBOOK/WWW-OAuth-1.000/source/lib/WWW/OAuth.pm#L86

Credits
-------
Robert Rothenberg (RRWO), finder

Reply via email to