๐Ÿ” CVE Alert

CVE-2026-16235

CRITICAL 9.8

Crypt::Password versions through 0.28 for Perl generate insecure random values for salts

CVSS Score
9.8
EPSS Score
0.1%
EPSS Percentile
4th

Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography.

CWE CWE-338
Vendor drsteve
Product crypt::password
Published Jul 20, 2026
Last Updated Jul 20, 2026
Stay Ahead of the Next One

Get instant alerts for drsteve crypt::password

Be the first to know when new critical vulnerabilities affecting drsteve crypt::password are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

DRSTEVE / Crypt::Password
0 โ‰ค 0.28

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
metacpan.org: https://metacpan.org/release/DRSTEVE/Crypt-Password-0.28/source/lib/Crypt/Password.pm#L306-309 openwall.com: http://www.openwall.com/lists/oss-security/2026/07/20/3