CVE-2025-40905
HIGHWWW::OAuth <1.000 - Info Disclosure
Title source: llmDescription
WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.
References (4)
Scores
CVSS v3
7.3
EPSS
0.0005
EPSS Percentile
15.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Classification
CWE
CWE-338
Status
draft
Timeline
Published
Feb 13, 2026
Tracked Since
Feb 18, 2026