CVE-2026-5088Disclosure(jdeguest / apache\)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache::API::Password versions through 0.5.2 for Perl can generate insecure random values for salts. The _make_salt and _make_salt_bcrypt methods will attept to load Crypt::URandom and then Bytes::Random::Secure to generate random bytes for the salt. If those modules are unavailable, it will simply return 16 bytes generated with Perl's built-in rand function. The rand function is unsuitable for cryptographic use. These salts are used for password hashing.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-338

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • apache\

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
apache\

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-15: 2Technical Details · 2026-04-15: 204-15
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-5088: Apache::API::Password versions through 0.5.2 can generate insecure random values for salts https://www.openwall.com/lists/oss-security/2026/04/15/4

    Post summary

    The note announces CVE‑2026‑5088, describing how Apache::API::Password produces insecure random salts, but provides no PoC, exploit, or patch details.

    00030453
    4.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5088 Apache::API::Password versions through v0.5.2 for Perl can generate insecure random values for salts. The _make_salt and _make_salt_bcrypt methods will attept to load … https://www.cve.org/CVERecord?id=CVE-2026-5088

    Post summary

    The text discloses CVE‑2026‑5088, noting that Apache::API::Password versions ≤ 0.5.2 generate weak salts via _make_salt functions, but provides no PoC, exploitation details, or patch.

    0000036
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjdeguestapache\\--

Explore more