CVE-2025-40905Disclosure(dbook / www\)

LOWCVSS 7.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch dbook www\ systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-338

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • www\

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 1 mentions (2026-02-12); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
www\

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-12: 1Mentions · 2026-02-13: 1Mentions · 2026-02-16: 1Mentions · 2026-02-18: 1Patch / Workaround · 2026-02-16: 1Technical Details · 2026-02-12: 1Technical Details · 2026-02-16: 1Technical Details · 2026-02-18: 102-1202-1302-1602-18
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-121
Disclosure1
2026-02-131
Disclosure1
2026-02-161
Patch1
2026-02-181
Disclosure1
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Patch

    CVE-2025-40905: WWW::OAuth 1.000 and earlier for Perl uses insecure rand() function for cryptographic functions https://www.openwall.com/lists/oss-security/2026/02/13/1 Upgrade to WWW::OAuth 1.001 or higher

    Post summary

    CVE-2025-40905 affects WWW::OAuth 1.000 and earlier due to insecure rand() usage; users should upgrade to 1.001 or newer to resolve the issue.

    00052645
    4.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-40905 WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. https://www.cve.org/CVERecord?id=CVE-2025-40905

    Post summary

    The text announces CVE‑2025‑40905, noting that the Perl WWW::OAuth module uses a non‑cryptographic rand() function for entropy, but does not mention any PoC, exploit, or mitigation details.

    00021725
    56.5K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2025-40905 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-40905 #CVE-2025-40905 #CVE #CyberSecurity #InfoSec https://t.co/2xDVL6O9yv

    Post summary

    The post announces a new CVE (CVE‑2025‑40905) with minimal details and links only to the NVD entry; it offers no exploit, patch, or technical information.

    0001044
    57 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-40905 (CVSS:7.3, HIGH) is Awaiting Analysis. WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptograp..https://nvd.nist.gov/vuln/detail/CVE-2025-40905 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE‑2025‑40905, highlighting that WWW::OAuth uses insecure rand() for entropy with a CVSS score of 7.3. No PoC, exploit code, patch, or active exploitation information is provided.

    0000034
    171 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdbookwww\\--

Explore more