CVE-2026-9638: high-severity vulnerability in ARODLAND Crypt::PBKDF2
Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts
Published
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 0.5%
exploitation probability
0.5%top 60% of all CVEs
observed exploitation
nono source reports it
Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts.
These versions use the built-in rand function, which is predictable and unsuitable for cryptography.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
ARODLAND · Crypt::PBKDF2Related CVEs — ARODLAND Crypt::PBKDF2
In the same product, most dangerous first.