HIGH🇵🇱 Wersja polska

CVE-2026-18536

CVSS 7.5pub. 2026-08-01upd. 2026-08-07

Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource::RandomOrg and Data::Entropy::RawSource::RandomnumbersInfo remote sources are accessed over plain HTTP. The Data::Entropy::RawSource::RandomOrg integrity check trivially matches any non-empty byte string. Any on-path attacker, such as open WiFi, a compromised ISP, captive portal, or a hostile egress proxy substitutes the response and thereby chooses the bytes returned by rand_bits and rand_int for every application that selected one of these sources via with_entropy_source. The _checkbuf method response is equally attacker-controlled, so the retry/sleep behaviour is steerable too.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Rrwo Data\

    APP
    Rrwo
    \
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-49941HIGH7.5same vendor

Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses. The add method called the _encod...

CVE-2026-49942HIGH7.3same vendor

Net::CIDR::Set versions through 0.20 for Perl did not validate network masks. The mask portion of a network m...

CVE-2026-7040HIGH7.5same vendor

Text::Minify::XS versions from 0.3.0 before 0.7.8 for Perl have a heap overflow when processing some malformed...

CVE-2026-49940MEDIUM6.5same vendor

Wersje Net::CIDR::Set do 0.20 dla Perl'a akceptują adresy IP i maski sieciowe zawierające znaki spoza zakresu ...