๐Ÿ” CVE Alert

CVE-2026-46473

HIGH 7.5

Authen::TOTP versions before 0.1.1 for Perl generate secrets using rand

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

Authen::TOTP versions before 0.1.1 for Perl generate secrets using rand. Secrets were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage.

CWE CWE-331
Vendor tchatzi
Product authen::totp
Published May 21, 2026
Last Updated May 21, 2026
Stay Ahead of the Next One

Get instant alerts for tchatzi authen::totp

Be the first to know when new high vulnerabilities affecting tchatzi authen::totp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

TCHATZI / Authen::TOTP
0 < 0.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
metacpan.org: https://metacpan.org/release/TCHATZI/Authen-TOTP-0.1.1/changes github.com: https://github.com/tchatzi/Authen-TOTP/commit/d04f30cc6538d77fc6b6d550da450cf3017b8561.patch openwall.com: http://www.openwall.com/lists/oss-security/2026/05/21/15