๐Ÿ” CVE Alert

CVE-2026-6659

HIGH 7.5

Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography.

CWE CWE-338
Vendor rsavage
Product crypt::passwdmd5
Published May 8, 2026
Last Updated May 8, 2026
Stay Ahead of the Next One

Get instant alerts for rsavage crypt::passwdmd5

Be the first to know when new high vulnerabilities affecting rsavage crypt::passwdmd5 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

RSAVAGE / Crypt::PasswdMD5
0 โ‰ค 1.42

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
metacpan.org: https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.42/source/lib/Crypt/PasswdMD5.pm#L35-47 openwall.com: http://www.openwall.com/lists/oss-security/2026/05/08/17