
Perl CPAN CVE-2025-15604: Amon2 versions before 6.17 use an insecure random_string implementation for security functions https://www.openwall.com/lists/oss-security/2026/03/28/4 CVE-2026-3256: HTTP::Session versions through 0.53 defaults to using insecurely generated session ids https://www.openwall.com/lists/oss-security/2026/03/28/5
Post summary
The text discloses two Perl CPAN modules (Amon2 <6.17 and HTTP::Session <=0.53) with insecure random string and session-id generation, respectively, providing CVE details but no PoC, exploit, or patch information.


