{"api_version":"1","generated_at":"2026-07-23T15:44:51+00:00","cve":"CVE-2026-6146","urls":{"html":"https://cve.report/CVE-2026-6146","api":"https://cve.report/api/cve/CVE-2026-6146.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-6146","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-6146"},"summary":{"title":"Amazon::Credentials versions through 1.2.0 for Perl uses rand to generate encryption keys","description":"Amazon::Credentials versions through 1.2.0 for Perl uses rand to generate encryption keys.\n\nAmazon::Credentials stores credentials in an obfuscated form to prevent access to the secrets from a data dump of the object.\n\nBefore version 1.3.0, the secrets were encrypted using a 64-bit key that was generated using the built-in rand function, which is predictable and unsuitable for cryptography.","state":"PUBLISHED","assigner":"CPANSec","published_at":"2026-05-11 20:25:47","updated_at":"2026-05-12 16:48:58"},"problem_types":["CWE-338","CWE-338 CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)"],"metrics":[],"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/05/11/15","name":"http://www.openwall.com/lists/oss-security/2026/05/11/15","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://metacpan.org/release/BIGFOOT/Amazon-Credentials-1.2.0/source/lib/Amazon/Credentials.pm#L1415-1418","name":"https://metacpan.org/release/BIGFOOT/Amazon-Credentials-1.2.0/source/lib/Amazon/Credentials.pm#L1415-1418","refsource":"9b29abf9-4ab0-4765-b253-1875cd9b441e","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://metacpan.org/release/BIGFOOT/Amazon-Credentials-1.3.0/changes","name":"https://metacpan.org/release/BIGFOOT/Amazon-Credentials-1.3.0/changes","refsource":"9b29abf9-4ab0-4765-b253-1875cd9b441e","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-6146","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6146","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"BIGFOOT","product":"Amazon::Credentials","version":"affected 1.2.0 custom","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"Upgrade to version 1.3.0 or later.","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"6146","cve":"CVE-2026-6146","epss":"0.000130000","percentile":"0.019970000","score_date":"2026-05-12","updated_at":"2026-05-13 00:11:52"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2026-05-11T21:29:37.446Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/05/11/15"}],"title":"CVE Program Container"}],"cna":{"affected":[{"collectionURL":"https://cpan.org/modules","defaultStatus":"unaffected","packageName":"Amazon-Credentials","product":"Amazon::Credentials","programFiles":["lib/Amazon/Credentials.pm"],"programRoutines":[{"name":"Amazon::Credentials::create_passkey"}],"repo":"https://github.com/rlauer6/Amazon-Credentials","vendor":"BIGFOOT","versions":[{"lessThanOrEqual":"1.2.0","status":"affected","version":"0","versionType":"custom"}]}],"descriptions":[{"lang":"en","value":"Amazon::Credentials versions through 1.2.0 for Perl uses rand to generate encryption keys.\n\nAmazon::Credentials stores credentials in an obfuscated form to prevent access to the secrets from a data dump of the object.\n\nBefore version 1.3.0, the secrets were encrypted using a 64-bit key that was generated using the built-in rand function, which is predictable and unsuitable for cryptography."}],"problemTypes":[{"descriptions":[{"cweId":"CWE-338","description":"CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-05-11T19:12:17.630Z","orgId":"9b29abf9-4ab0-4765-b253-1875cd9b441e","shortName":"CPANSec"},"references":[{"url":"https://metacpan.org/release/BIGFOOT/Amazon-Credentials-1.2.0/source/lib/Amazon/Credentials.pm#L1415-1418"},{"tags":["release-notes"],"url":"https://metacpan.org/release/BIGFOOT/Amazon-Credentials-1.3.0/changes"}],"solutions":[{"lang":"en","value":"Upgrade to version 1.3.0 or later."}],"source":{"discovery":"UNKNOWN"},"title":"Amazon::Credentials versions through 1.2.0 for Perl uses rand to generate encryption keys","x_generator":{"engine":"cpansec-cna-tool 0.1"}}},"cveMetadata":{"assignerOrgId":"9b29abf9-4ab0-4765-b253-1875cd9b441e","assignerShortName":"CPANSec","cveId":"CVE-2026-6146","datePublished":"2026-05-11T19:12:17.630Z","dateReserved":"2026-04-12T17:24:50.568Z","dateUpdated":"2026-05-11T21:29:37.446Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-05-11 20:25:47","lastModifiedDate":"2026-05-12 16:48:58","problem_types":["CWE-338","CWE-338 CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"6146","Ordinal":"1","Title":"Amazon::Credentials versions through 1.2.0 for Perl uses rand to","CVE":"CVE-2026-6146","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"6146","Ordinal":"1","NoteData":"Amazon::Credentials versions through 1.2.0 for Perl uses rand to generate encryption keys.\n\nAmazon::Credentials stores credentials in an obfuscated form to prevent access to the secrets from a data dump of the object.\n\nBefore version 1.3.0, the secrets were encrypted using a 64-bit key that was generated using the built-in rand function, which is predictable and unsuitable for cryptography.","Type":"Description","Title":"Amazon::Credentials versions through 1.2.0 for Perl uses rand to"}]}}}