logo

CVE-2026-16235: Perl Crypt::Password Generates Predictable Salts, Enabling Password Hash Cracking

ID: c583551b-61ea-590c-91c1-5721d0170af8

STIX ID: report--c583551b-61ea-590c-91c1-5721d0170af8

Feed Name: CosmicBytez Labs

Threat Score
75/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

...
...

This report discloses a critical vulnerability (CVE-2026-16235, CVSS 9.8) in the Crypt::Password Perl module through v0.28 where salts are generated with Perl's non-cryptographic rand(), making stored password hashes predictable and highly susceptible to offline dictionary and brute-force attacks; remediation includes upgrading to v0.29+, re-hashing passwords on next login, and rotating affected credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.