
Perl CPAN CVE-2026-8503: Apache::Session::Generate::SHA256 before 1.3.19 create insecure session ids https://www.openwall.com/lists/oss-security/2026/05/15/16 CVE-2026-46474: Trog::TOTP before 1.006 generate secrets using rand https://www.openwall.com/lists/oss-security/2026/05/15/18
Post summary
The post announces two Perl CPAN CVEs, detailing insecure session ID creation and weak secret generation, and provides mailing list links for further reading.
