
Perl CPAN CVE-2026-14570: Crypt::DSA before 1.22 draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery https://www.openwall.com/lists/oss-security/2026/07/05/1
Post summary
The CVE-2026-14570 vulnerability in Crypt::DSA before 1.22 is a private-key recovery flaw due to a biased RNG, with the announcement providing technical details but no PoC, patch, or evidence of active exploitation.
