Trog::TOTP versions before 1.006 for Perl generate secrets using rand.
Secrets were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage.
Metrics
Affected Vendors & Products
References
History
Fri, 15 May 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 15 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Trog::TOTP versions before 1.006 for Perl generate secrets using rand. Secrets were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage. | |
| Title | Trog::TOTP versions before 1.006 for Perl generate secrets using rand | |
| Weaknesses | CWE-331 | |
| References |
|
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-05-15T21:23:28.941Z
Reserved: 2026-05-14T17:55:07.623Z
Link: CVE-2026-46474
No data.
Status : Received
Published: 2026-05-15T18:16:26.053
Modified: 2026-05-15T22:16:56.637
Link: CVE-2026-46474
No data.
OpenCVE Enrichment
Updated: 2026-05-15T19:30:05Z