Junglewise Threat Intelligence

CVE-2026-16615: GNOME librest weak PRNG in OAuth PKCE implementation

CVE-2026-16615 · Severity: medium · CVSS 6.8 · Published 2026-07-22

Technologies: Red Hat Enterprise Linux 10. Vendors: Gnome, Red Hat.

Executive brief

A security flaw was found in librest, a software library used by applications to interact with web services. The library uses a weak method for generating security codes during the login process (OAuth), making these codes predictable. An attacker could exploit this to impersonate a legitimate user or application, potentially gaining unauthorized access to account data.

Technical details

A vulnerability exists in librest's PKCE implementation for OAuth 2.0. The 'random_string' function in 'rest/rest-utils.c' utilizes the GLib 'GRand' API, which is based on the Mersenne Twister algorithm and is not cryptographically secure. Because this PRNG lacks sufficient entropy, an attacker can reverse-engineer the seed to predict or reconstruct the 'code verifier' string. This allows a remote attacker to bypass PKCE protections and successfully impersonate the client during the authorization flow. The issue affects all versions of librest and requires the attacker to intercept or participate in an OAuth flow where PKCE is utilized.

Affected products

  • GNOME librest All versions
  • Red Hat Red Hat Enterprise Linux 10

Timeline

  • 2026-07-21: disclosed: Issue reported via Red Hat Bugzilla and GNOME GitLab
  • 2026-07-22: advisory: NVD and Red Hat published advisory details

References