CVE-2026-9638highCWE-338

CVE-2026-9638: high-severity vulnerability in ARODLAND Crypt::PBKDF2

Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts

Published

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 0.5%
exploitation probability
0.5%top 60% of all CVEs
observed exploitation
nono source reports it
Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
ARODLAND · Crypt::PBKDF2