CVE-2026-47372Disclosure

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-338

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-21); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-21: 2Mentions · 2026-06-11: 1Technical Details · 2026-05-21: 2Technical Details · 2026-06-11: 105-2106-11
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-212
Disclosure2
2026-06-111
Disclosure1
Full discourse3 posts
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    🛡️ Se você usa Ubuntu, verifique sua versão do libcrypt-saltedhash-perl agora mesmo! Uma vulnerabilidade (CVE-2026-47372) permite prever salts de hashes. Saiba mais: -> http://tinyurl.com/vk9zybu2 #Ubuntu https://t.co/m4FVAouYJ1

    Post summary

    A tweet alerts Ubuntu users to CVE‑2026‑47372 in libcrypt‑saltedhash‑perl, noting it can predict hash salts, but provides no PoC, exploit, or patch details.

    1001045
    1.5K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-47372: Crypt::SaltedHash through 0.09 generate insecure random values for salts https://www.openwall.com/lists/oss-security/2026/05/20/22 CVE-2026-47373: Crypt::SaltedHash through 0.09 is susceptible to timing attacks https://www.openwall.com/lists/oss-security/2026/05/20/21

    Post summary

    The excerpt announces two CVEs for Crypt::SaltedHash, highlighting insecure random salt values and timing attack risks, with no mention of exploit code or patch details.

    10000333
    4.6K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    ⚠️⚠️⚠️ 『These versions use the built-in rand function, which is predictable and unsuitable for cryptography.』 oss-security - CVE-2026-47372: Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts https://www.openwall.com/lists/oss-security/2026/05/20/22

    Post summary

    The advisory announces that Crypt::SaltedHash through version 0.09 generates insecure, predictable salts due to the built‑in rand function; no exploit, patch, or PoC details are provided.

    00000300
    6.9K followersView on X

Explore more