CVE-2026-6146
MEDIUMAmazon::Credentials versions through 1.2.0 for Perl uses rand to generate encryption keys
Title source: cnaDescription
Amazon::Credentials versions through 1.2.0 for Perl uses rand to generate encryption keys. Amazon::Credentials stores credentials in an obfuscated form to prevent access to the secrets from a data dump of the object. Before version 1.3.0, the secrets were encrypted using a 64-bit key that was generated using the built-in rand function, which is predictable and unsuitable for cryptography.
References (3)
Core 3
Core References
Release Notes release-notes
https://metacpan.org/release/BIGFOOT/Amazon-Credentials-1.3.0/changes
Scores
CVSS v3
5.3
EPSS
0.0017
EPSS Percentile
7.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-338
Status
published
Products (1)
BIGFOOT/Amazon::Credentials
< 1.2.0
Published
May 11, 2026
Tracked Since
May 12, 2026