Executive brief
Crypt::Password is a Perl library used by developers to handle password hashing and security. A vulnerability was discovered where the library uses a predictable method to generate the 'salt' values used to protect passwords. This could allow an attacker to more easily crack user passwords if they obtain access to the hashed password database, potentially leading to unauthorized account access.
Technical details
The Crypt::Password library (up to version 0.28) utilizes Perl's built-in 'rand' function within the '_invent_salt' routine to generate password salts. This function is a cryptographically weak pseudo-random number generator (PRNG) and is predictable, violating requirements for cryptographic security (CWE-338). An attacker with access to password hashes could leverage this predictability to perform more efficient offline brute-force or rainbow table attacks. The vulnerability is rooted in the 'lib/Crypt/Password.pm' file. Users are advised to check for updates or migrate to libraries using cryptographically secure PRNGs like 'Bytes::Random::Secure'.
Affected products
- DRSTEVE (CPAN) Crypt::Password 0 through 0.28
Timeline
- 2026-07-20: disclosed: CVE published to NVD dataset