CVE-2026-16235: Perl Crypt::Password Generates Predictable Salts, Enabling Password Hash Cracking
ID: c583551b-61ea-590c-91c1-5721d0170af8
STIX ID: report--c583551b-61ea-590c-91c1-5721d0170af8
Feed Name: CosmicBytez Labs
Threat Score
This report discloses a critical vulnerability (CVE-2026-16235, CVSS 9.8) in the Crypt::Password Perl module through v0.28 where salts are generated with Perl's non-cryptographic rand(), making stored password hashes predictable and highly susceptible to offline dictionary and brute-force attacks; remediation includes upgrading to v0.29+, re-hashing passwords on next login, and rotating affected credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
