
Perl CPAN CVE-2026-5086: Crypt::SecretBuffer versions before 0.019 is susceptible to timing attacks https://www.openwall.com/lists/oss-security/2026/04/13/12 For example, if it was used to store and compare plaintext passwords, then discrepancies in timing could be used to guess the secret password
Post summary
The text announces CVE‑2026‑5086 as a timing‑attack vulnerability in Crypt::SecretBuffer, but gives no exploit code, patch, or evidence of active exploitation.

