Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-18536

Опубликовано: 01 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource::RandomOrg and Data::Entropy::RawSource::RandomnumbersInfo remote sources are accessed over plain HTTP. The Data::Entropy::RawSource::RandomOrg integrity check trivially matches any non-empty byte string. Any on-path attacker, such as open WiFi, a compromised ISP, captive portal, or a hostile egress proxy substitutes the response and thereby chooses the bytes returned by rand_bits and rand_int for every application that selected one of these sources via with_entropy_source. The _checkbuf method response is equally attacker-controlled, so the retry/sleep behaviour is steerable too.

A flaw was found in Data-Entropy. This component reads remote entropy (randomness) sources over unencrypted HTTP. An on-path attacker, such as one on an open Wi-Fi network or a compromised internet service provider (ISP), can intercept and alter the responses from these sources. This allows the attacker to control the random bytes generated by the application, leading to predictable random numbers. Such a compromise of cryptographic randomness can have significant security implications, potentially enabling further attacks.

Отчет

This Important flaw in perl-Data-Entropy allows an on-path attacker to manipulate random number generation by intercepting unencrypted HTTP requests to specific remote entropy sources. This can lead to predictable values in applications configured to use these insecure sources, compromising cryptographic randomness and potentially leading to severe security vulnerabilities. Note that Data::Entropy has been deprecated since version 0.008. Users are advised to migrate to alternative solutions that use system sources of random data, such as Crypt::SysRandom, Crypt::URandom or Crypt::PRNG.

Меры по смягчению последствий

Deployments should not use the RandomOrg or RandomnumbersInfo sources, as these are flawed. They have been removed from Data::Entropy 0.010. (There was a change to use HTTPS to connect to these sources in version 0.009 that did not work.) Note that Data::Entropy has been deprecated since version 0.008. Users are advised to migrate to alternative solutions that use system sources of random data, such as Crypt::SysRandom, Crypt::URandom or Crypt::PRNG.

Дополнительная информация

Статус:

Important
Дефект:
CWE-319
https://bugzilla.redhat.com/show_bug.cgi?id=2509968Data-Entropy: Data-Entropy: Predictable random numbers due to unencrypted remote entropy sources

EPSS

Процентиль: 6%
0.00161
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
16 дней назад

Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource::RandomOrg and Data::Entropy::RawSource::RandomnumbersInfo remote sources are accessed over plain HTTP. The Data::Entropy::RawSource::RandomOrg integrity check trivially matches any non-empty byte string. Any on-path attacker, such as open WiFi, a compromised ISP, captive portal, or a hostile egress proxy substitutes the response and thereby chooses the bytes returned by rand_bits and rand_int for every application that selected one of these sources via with_entropy_source. The _checkbuf method response is equally attacker-controlled, so the retry/sleep behaviour is steerable too.

CVSS3: 7.5
nvd
16 дней назад

Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource::RandomOrg and Data::Entropy::RawSource::RandomnumbersInfo remote sources are accessed over plain HTTP. The Data::Entropy::RawSource::RandomOrg integrity check trivially matches any non-empty byte string. Any on-path attacker, such as open WiFi, a compromised ISP, captive portal, or a hostile egress proxy substitutes the response and thereby chooses the bytes returned by rand_bits and rand_int for every application that selected one of these sources via with_entropy_source. The _checkbuf method response is equally attacker-controlled, so the retry/sleep behaviour is steerable too.

CVSS3: 7.5
debian
16 дней назад

Data::Entropy versions before 0.010 for Perl read remote entropy sourc ...

EPSS

Процентиль: 6%
0.00161
Низкий

7.5 High

CVSS3

Уязвимость CVE-2026-18536