Junglewise Threat Intelligence

CVE-2026-47372: Perl Crypt::SaltedHash weak PRNG in salt generation

CVE-2026-47372 · Severity: info · CVSS 0 · Published 2026-05-20

Vendors: Perl CPAN, CPAN.

Executive brief

Crypt::SaltedHash is a Perl library used to securely store passwords by adding a random 'salt' to them. Versions up to 0.09 use a weak method for generating these salts, making the resulting password hashes predictable. This could allow an attacker to more easily crack user passwords if they obtain access to the database.

Technical details

Crypt::SaltedHash through version 0.09 utilizes Perl's built-in rand() function to generate salts for password hashing. The rand() function is a cryptographically weak pseudo-random number generator (PRNG) that is predictable, violating the requirements for secure salt generation (CWE-338). An attacker with knowledge of the PRNG state or sufficient samples could predict future salts, facilitating pre-computation attacks (like rainbow tables) or offline brute-force attacks against the hashes. The vulnerability is addressed in version 0.10 by migrating to Crypt::SysRandom for cryptographically secure random byte generation.

Affected products

  • Perl CPAN Crypt::SaltedHash through 0.09

Timeline

  • 2026-05-19: patched: Version 0.10 released with fix.
  • 2026-05-20: disclosed: CVE-2026-47372 published.

References

Related threats