CWE-338

Medium likelihood

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

Parent: CWE-330 - Use of Insufficiently Random Values

The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.

205 vulnerabilities with CWE-338
CVE-2026-47882 HIGH
Spring Boot DevTools remote secret generated with a non-cryptographic PRNG
CVSS 8.3
CVE-2026-64798 CRITICAL
Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension
CVSS 9.1
CVE-2026-16615 MEDIUM
Librest: weak random number generation in pkce implementation
CVSS 6.8
CVE-2026-8169 HIGH
Extreme Networks Switch Engine (EXOS) - ExtremeXOS Debug-Mode Privilege Escalation via Weak PRNG
CVE-2026-13577 HIGH
Dancer2 versions through 2.1.0 for Perl generate insecure session ids when CSPRNG modules are unavailable
CVSS 8.2
CVE-2026-16235 CRITICAL
Crypt::Password versions through 0.28 for Perl generate insecure random values for salts
CVSS 9.8
CVE-2026-9323 HIGH
Insecure PRNG and Information Exposure in urwid Web Display Backend
CVSS 8.1
CVE-2026-13082 MEDIUM
GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets
CVSS 5.3
CVE-2026-63089 CRITICAL
WireGuard Easy Weak Token Generation Information Disclosure via OTL Route
CVSS 9.3
CVE-2026-61500 CRITICAL
Rejetto HFS < 3.2.1 Session Forgery via Predictable Signing Key
CVSS 9.8
CVE-2026-14495 HIGH
DoLogin Security <= 4.3 - Unauthenticated Authentication Bypass via Insufficient Randomness via 'dologin' Parameter Weak PRNG Token
CVSS 8.8
CVE-2026-56016 MEDIUM
CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources
CVSS 5.9
CVE-2026-7830 HIGH
UltraVNC MS-Logon II uses 64-bit Diffie-Hellman and seeded libc rand() enabling credential interception
CVSS 7.4
CVE-2026-44040 MEDIUM
UltraVNC vncauth.c uses time-seeded libc rand() to generate VNC authentication challenge bytes
CVSS 4.8
CVE-2026-7874 CRITICAL
IBM Langflow OSS - Weak Cryptographic Key Derivation Exposed All Stored Credentials
CVSS 9.1
CVE-2026-57082 MEDIUM
Net::BitTorrent versions through 2.0.1 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG
CVSS 5.9
CVE-2026-9733 CRITICAL
Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter
CVSS 9.1
CVE-2026-56141 CRITICAL
Jetbrains Hub - Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVSS 9.8
CVE-2026-9692 MEDIUM
Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely
CVSS 5.3
CVE-2026-11832 CRITICAL
Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce
CVSS 9.1
CVE-2026-9638 HIGH
Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts
CVSS 7.5
CVE-2026-46493 HIGH
haxtheweb/haxcms-php uses insecure method for generating salt
CVSS 7.5
CVE-2026-11347 HIGH
Hardcoded Cryptographic Keys and Weak IV Generation in Linqi Application
CVE-2026-41858 HIGH
Cloud Foundry Foundation Windows-utilities-release < 0.23.0 - Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVSS 7.5
CVE-2026-8647 MEDIUM
Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG module is available
CVSS 4.8
Details
Vulnerabilities 205
Exploit Likelihood Medium