Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.3

Perl WWW::OAuth uses insecure random number generator

CVE-2025-40905
Summary

WWW::OAuth for Perl may generate weak encryption keys, compromising the security of authentication and authorization processes. This could allow an attacker to intercept or manipulate sensitive information. To stay secure, update to the latest version of WWW::OAuth.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
dbook www\ \ –
Original title
WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.
Original description
WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.
nvd CVSS3.1 7.3
Vulnerability type
CWE-338
Published: 13 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026