๐Ÿ” CVE Alert

CVE-2026-8647

MEDIUM 4.8

Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG module is available

CVSS Score
4.8
EPSS Score
0.0%
EPSS Percentile
4th

Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG module is available. The random_bytes function fell back to using the built-in rand() function when none of the Perl modules Crypt::PRNG, Crypt::OpenSSL::Random, Net::SSLeay, Crypt::Random, or Bytes::Random::Secure were available.

CWE CWE-338
Vendor mik
Product crypt::scryptkdf
Published May 26, 2026
Last Updated May 28, 2026
Stay Ahead of the Next One

Get instant alerts for mik crypt::scryptkdf

Be the first to know when new medium vulnerabilities affecting mik crypt::scryptkdf are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

MIK / Crypt::ScryptKDF
0 โ‰ค 0.010

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
metacpan.org: https://metacpan.org/release/MIK/Crypt-ScryptKDF-0.011/changes metacpan.org: https://metacpan.org/release/MIK/Crypt-ScryptKDF-0.011/diff/MIK/Crypt-ScryptKDF-0.010#lib/Crypt/ScryptKDF.pm openwall.com: http://www.openwall.com/lists/oss-security/2026/05/26/8