CVE-2026-16615

MEDIUM

Librest: weak random number generation in pkce implementation

Title source: cna
STIX 2.1

Description

A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.

References (4)

Core 4
Core References
Vdb Entry, X_Refsource_Redhat vdb-entry x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2026-16615
Issue Tracking, X_Refsource_Redhat issue-tracking x_refsource_redhat
RHBZ#2504432
https://bugzilla.redhat.com/show_bug.cgi?id=2504432
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:47085
https://access.redhat.com/errata/RHSA-2026:47085

Scores

CVSS v3 6.8
EPSS 0.0025
EPSS Percentile 17.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-338
Status published
Products (3)
GNOME/librest
Red Hat/Red Hat Enterprise Linux 10
Red Hat/Red Hat Enterprise Linux 10 0:0.9.1-11.el10_2.1
Published Jul 22, 2026
Tracked Since Jul 22, 2026