Junglewise Threat Intelligence

CVE-2026-9638: Perl Crypt::PBKDF2 weak PRNG in salt generation

CVE-2026-9638 · Severity: info · CVSS 0 · Published 2026-06-12

Vendors: Perl CPAN.

Executive brief

Crypt::PBKDF2 is a Perl library used to securely hash passwords for storage. Older versions of this library used a weak method for generating the 'salt' (a random value added to passwords to prevent bulk cracking). This weakness makes it easier for attackers who obtain a database of hashed passwords to guess or crack them using pre-computed tables or specialized hardware.

Technical details

The Crypt::PBKDF2 library prior to version 0.261630 utilized Perl's built-in rand() function to generate salts for password hashing. This function is a cryptographically weak pseudo-random number generator (PRNG) and is predictable, which violates the requirements for secure salt generation in the PBKDF2 algorithm. An attacker with access to hashed passwords could potentially exploit this predictability to perform more efficient offline brute-force or rainbow table attacks. The vulnerability was addressed in version 0.261630 by migrating salt generation to Crypt::URandom, which utilizes the operating system's cryptographically secure PRNG.

Affected products

  • Perl CPAN Crypt::PBKDF2 before 0.261630

Timeline

  • 2026-06-11: patched: Version 0.261630 released with fix.
  • 2026-06-12: advisory: CVE-2026-9638 published.

References