Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP

Summary

CVECVE-2026-18536
StatePUBLISHED
AssignerCPANSec
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-01 11:16:38 UTC
Updated2026-08-01 16:16:30 UTC
DescriptionData::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource::RandomOrg and Data::Entropy::RawSource::RandomnumbersInfo remote sources are accessed over plain HTTP. The Data::Entropy::RawSource::RandomOrg integrity check trivially matches any non-empty byte string. Any on-path attacker, such as open WiFi, a compromised ISP, captive portal, or a hostile egress proxy substitutes the response and thereby chooses the bytes returned by rand_bits and rand_int for every application that selected one of these sources via with_entropy_source. The _checkbuf method response is equally attacker-controlled, so the retry/sleep behaviour is steerable too.

Risk And Classification

Problem Types: CWE-319 | CWE-353 | CWE-319 CWE-319 Cleartext Transmission of Sensitive Information | CWE-353 CWE-353 Missing Support for Integrity Check

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA RRWO DataEntropy affected 0.010 custom Not specified

References

ReferenceSourceLinkTags
metacpan.org/release/RRWO/Data-Entropy-0.010/changes 9b29abf9-4ab0-4765-b253-1875cd9b441e metacpan.org
github.com/robrwo/Data-Entropy/security/advisories/GHSA-845w-rcqw-jwvv 9b29abf9-4ab0-4765-b253-1875cd9b441e github.com
security.metacpan.org/docs/guides/random-data-for-security.html 9b29abf9-4ab0-4765-b253-1875cd9b441e security.metacpan.org
www.openwall.com/lists/oss-security/2026/08/01/8 af854a3a-2127-422b-91ae-364da2661108 www.openwall.com
metacpan.org/release/RRWO/Data-Entropy-0.008/view/lib/Data/Entropy.pm 9b29abf9-4ab0-4765-b253-1875cd9b441e metacpan.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Additional Advisory Data

Workarounds

CNA: Deployments should not use the RandomOrg or RandomnumbersInfo sources, as these are flawed. They have been removed from Data::Entropy 0.010. (There was a change to use HTTPS to connect to these sources in version 0.009 that did not work.) Note that Data::Entropy has been deprecated since version 0.008. Users are advised to migrate to alternative solutions that use system sources of random data, such as Crypt::SysRandom, Crypt::URandom or Crypt::PRNG.

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report