Executive brief
GD::SecurityImage is a Perl library used to generate CAPTCHA images to distinguish between human users and automated bots. A security flaw in the library uses a predictable method for generating the challenge text, which could allow an attacker to programmatically guess the CAPTCHA. This undermines the security of web forms, potentially leading to automated spam, account brute-forcing, or other bot-driven attacks.
Technical details
GD::SecurityImage through version 1.75 utilizes Perl's built-in rand() function within its random() method to generate CAPTCHA challenge strings. Because rand() is a non-cryptographic PRNG, the output is predictable and reversible if the internal state is discovered. An attacker can exploit this to programmatically predict the CAPTCHA text, bypassing automated-interaction protections (CWE-338, CWE-804). The vulnerability affects the random(), random_angle(), and particle() routines. A patch has been made available via CPANSec.
Affected products
- BURAK (CPAN) GD::SecurityImage through 1.75
Timeline
- 2026-07-17: disclosed: CVE published to NVD dataset
- 2026-07-17: advisory