Executive brief
Authen::TOTP, a Perl library used for generating two-factor authentication (2FA) codes, used a weak method for creating security secrets. Because these secrets were generated using a predictable mathematical function, an attacker might be able to guess them and bypass 2FA protections. This could lead to unauthorized access to user accounts and sensitive data.
Technical details
Authen::TOTP prior to version 0.1.1 utilized Perl's built-in rand() function within the gen_secret() method to generate TOTP shared secrets. The rand() function is a deterministic pseudorandom number generator (PRNG) that is not cryptographically secure, making the resulting secrets predictable if the PRNG state can be determined. An attacker who can predict the generated secret can generate valid TOTP tokens, effectively bypassing two-factor authentication. The vulnerability is addressed in version 0.1.1 by migrating to Crypt::PRNG::random_string_from() for cryptographically secure secret generation.
Affected products
- Perl CPAN Authen::TOTP < 0.1.1
Timeline
- 2026-05-18: patched: Version 0.1.1 released using Crypt::PRNG
- 2026-05-21: disclosed: CVE-2026-46473 published