Open Source Security mailing list@oss_securityPatch
CVE-2025-40905 affects WWW::OAuth 1.000 and earlier due to insecure rand() usage; users should upgrade to 1.001 or newer to resolve the issue.
CVE@CVEnewDisclosure
The text announces CVE‑2025‑40905, noting that the Perl WWW::OAuth module uses a non‑cryptographic rand() function for entropy, but does not mention any PoC, exploit, or mitigation details.
CVEarity@CVEarityDisclosure
The post announces a new CVE (CVE‑2025‑40905) with minimal details and links only to the NVD entry; it offers no exploit, patch, or technical information.
CRAC Learning - Tech@cracbotDisclosure
The post announces CVE‑2025‑40905, highlighting that WWW::OAuth uses insecure rand() for entropy with a CVSS score of 7.3. No PoC, exploit code, patch, or active exploitation information is provided.