
Perl CPAN CVE-2026-47372: Crypt::SaltedHash through 0.09 generate insecure random values for salts https://www.openwall.com/lists/oss-security/2026/05/20/22 CVE-2026-47373: Crypt::SaltedHash through 0.09 is susceptible to timing attacks https://www.openwall.com/lists/oss-security/2026/05/20/21
Post summary
The announcement discloses two new CVEs in Crypt::SaltedHash v0.09—one involving insecure salt generation and the other enabling timing attacks—with no PoC, exploit code, active exploitation, or patch details provided.
