Junglewise Threat Intelligence

CVE-2026-6659: Crypt::PasswdMD5 weak PRNG in salt generation

CVE-2026-6659 · Severity: high · CVSS 7.5 · Published 2026-05-08

Vendors: Perl CPAN.

Executive brief

Crypt::PasswdMD5 is a Perl library used to generate MD5-based password hashes for Unix and Apache authentication. A security flaw was identified where the library uses a predictable random number generator to create password 'salts,' which are meant to protect passwords from being easily cracked. This weakness could allow an attacker to more easily guess or crack user passwords, potentially leading to unauthorized account access.

Technical details

Crypt::PasswdMD5 through version 1.42 utilizes Perl's built-in rand() function within the random_md5_salt() subroutine. This function is a cryptographically weak pseudo-random number generator (PRNG) that is predictable and unsuitable for security-sensitive operations like salt generation. An attacker who can predict the salt values can significantly reduce the computational effort required to perform pre-computation or brute-force attacks against password hashes generated by the library. The vulnerability is addressed in version 1.43 by replacing rand() with Crypt::URandom::urandom().

Affected products

  • Ron Savage Crypt::PasswdMD5 through 1.42

Timeline

  • 2026-05-08: disclosed: Vulnerability disclosed on oss-security mailing list
  • 2026-05-08: advisory: CVE-2026-6659 published
  • 2026-05-22: patched: Fix committed to GitHub repository
  • 2026-05-23: other: Version 1.43 released to CPAN

References