Showing 1 vulnerability on this page for librest

Signals CISA KEV Ransomware Nuclei
GNOME vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Librest: weak random number generation in pkce implementation

A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAut

CWE-338Jul 22, 2026
CVSS6.8v3.1EPSS0.254%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX