CVE-2026-6656
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Summary
Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks.
The check_password method uses the built-in eq operator. This allows discrepancies in timing to be used to guess the underlying hash.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| DRSTEVE | Crypt::Password | 0 <= 0.28 | affected |
Weaknesses
- CWE-208: CWE-208 Observable Timing Discrepancy
Workarounds
This module has not been updated since 2012.
Users should migrate to an alternative solution.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
CVE Program Container
Additional References
References
- https://metacpan.org/release/DRSTEVE/Crypt-Password-0.28/source/lib/Crypt/Password.pm#L190-193
- https://rt.cpan.org/Ticket/Display.html?id=180162
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.