High severity7.3NVD Advisory· Published Feb 13, 2026· Updated Jun 17, 2026
CVE-2025-40905
CVE-2025-40905
Description
WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <=1.000
- Range: 0
Patches
Vulnerability mechanics
References
4- www.openwall.com/lists/oss-security/2026/02/13/1nvdMailing ListThird Party Advisory
- perldoc.perl.org/functions/randnvdThird Party Advisory
- security.metacpan.org/docs/guides/random-data-for-security.htmlnvdThird Party Advisory
- metacpan.org/release/DBOOK/WWW-OAuth-1.000/source/lib/WWW/OAuth.pmnvdIssue TrackingProduct
News mentions
0No linked articles in our index yet.