CVE-2025-15638Disclosure(atrodo / net\)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt. Net::Dropbear versions before 0.14 includes versions of Dropbear 2019.78 or earlier. These include versions of libtomcrypt v1.18.1 or earlier, which is affected by CVE-2016-6129 and CVE-2018-12437.

0.0/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • net\

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-04-21); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
net\

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-21: 2Mentions · 2026-04-22: 1Mentions · 2026-04-28: 1Technical Details · 2026-04-21: 2Technical Details · 2026-04-22: 1Technical Details · 2026-04-28: 104-2104-2204-28
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-212
Disclosure2
2026-04-221
General1
2026-04-281
Disclosure1
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2017-20230: Storable stack buffer overflow https://www.openwall.com/lists/oss-security/2026/04/21/5 CVE-2025-15638: Net::Dropbear contains vulnerable libtomcrypt https://www.openwall.com/lists/oss-security/2026/04/21/6 CVE-2026-41564: CryptX did not reseed the Crypt::PK PRNG state after forking https://www.openwall.com/lists/oss-security/2026/04/23/2

    Post summary

    The text lists Perl CPAN CVEs with brief technical descriptions but does not mention PoC, exploit code, active exploitation, patches, or mitigation steps.

    000501.0K
    4.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-15638 Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt. Net::Dropbear versions before 0.14 includes versions of Dropbear 2019.78 or… https://www.cve.org/CVERecord?id=CVE-2025-15638

    Post summary

    The post announces CVE-2025-15638, detailing vulnerable Net::Dropbear versions and the use of libtomcrypt, but provides no evidence of exploits, patches, or active attacks.

    00010158
    57.2K followersView on X
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2025-15638 | CVSS 10.0 🔴 CVE-2026-40911 | CVSS 10.0 🔴 CVE-2017-20230 | CVSS 10.0 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post lists three CVEs with CVSS 10.0 scores and a link to a website, but provides no proof‑of‑concept, exploit, patch, or in‑depth technical details, making it a general vulnerability notice.

    00000345
    5.6K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-15638 Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt. Net::Dropbear versions before 0.14 includes versions of Dropbear 2019.78 or… https://www.cve.org/CVERecord?id=CVE-2025-15638 ----- Traducción: CVE-2025-15638 Net… http://infoflow.cloud`

    Post summary

    The tweet announces a new CVE—CVE-2025-15638—impacting Net::Dropbear versions before 0.14 due to a flaw in libtomcrypt, with no exploit or patch information provided.

    00000171
    72 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appatrodonet\\--

Explore more