Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.3
Perl WWW::OAuth uses insecure random number generator
CVE-2025-40905
Summary
WWW::OAuth for Perl may generate weak encryption keys, compromising the security of authentication and authorization processes. This could allow an attacker to intercept or manipulate sensitive information. To stay secure, update to the latest version of WWW::OAuth.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| dbook | www\ | \ | – |
Original title
WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.
Original description
WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.
nvd CVSS3.1
7.3
Vulnerability type
CWE-338
Published: 13 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026