๐Ÿ” CVE Alert

CVE-2026-6656

HIGH 7.5

Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks

CVSS Score
7.5
EPSS Score
0.1%
EPSS Percentile
4th

Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the built-in eq operator. This allows discrepancies in timing to be used to guess the underlying hash.

CWE CWE-208
Vendor drsteve
Product crypt::password
Published Jul 20, 2026
Last Updated Jul 20, 2026
Stay Ahead of the Next One

Get instant alerts for drsteve crypt::password

Be the first to know when new high vulnerabilities affecting drsteve crypt::password are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

DRSTEVE / Crypt::Password
0 โ‰ค 0.28

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
metacpan.org: https://metacpan.org/release/DRSTEVE/Crypt-Password-0.28/source/lib/Crypt/Password.pm#L190-193 rt.cpan.org: https://rt.cpan.org/Ticket/Display.html?id=180162 openwall.com: http://www.openwall.com/lists/oss-security/2026/07/20/4