CVE-2026-13082
MEDIUMGD::SecurityImage versions through 1.75 for Perl use rand to generate secrets
Title source: cnaDescription
GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets. The random method creates the challenge text used for the CAPTCHA by sampling characters from an array using Perl's built-in rand function, and generates a (by default) six-character string. The built-in rand function is unsuitable for security applications because it is predictable and reversible.
References (2)
Core 2
Core References
Related related
https://www.cve.org/CVERecord?id=CVE-2025-40916
Scores
CVSS v3
5.3
EPSS
0.0022
EPSS Percentile
12.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-338
CWE-804
Status
published
Products (1)
BURAK/GD::SecurityImage
< 1.75
Published
Jul 17, 2026
Tracked Since
Jul 17, 2026