CVE-2026-14570Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery. "Crypt::DSA::Util::makerandom forces the high bit of every value it returns to obtain an exactly N-bit integer for prime search. The signing nonce and the private key are drawn from makerandom. Because the high bit is always set, the result is not uniform: its top bit is fixed, producing insecure values." An attacker who collects a modest number of signatures under an affected key, together with the public key, can recover the private key with a lattice attack. Keys used to sign with an affected version should be considered compromised and new keys should be generated.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-330

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-05: 1Technical Details · 2026-07-05: 107-05
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-14570: Crypt::DSA before 1.22 draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery https://www.openwall.com/lists/oss-security/2026/07/05/1

    Post summary

    The CVE-2026-14570 vulnerability in Crypt::DSA before 1.22 is a private-key recovery flaw due to a biased RNG, with the announcement providing technical details but no PoC, patch, or evidence of active exploitation.

    10010249
    4.7K followersView on X

Explore more