Common Weakness Enumeration

CWE-338

Allowed

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

Abstraction: Base · Status: Draft

The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.

344 vulnerabilities reference this CWE, most recent first.

GHSA-4C72-MRHF-23CG

Vulnerability from github – Published: 2022-05-14 02:52 – Updated: 2023-08-15 22:11
VLAI
Summary
Apache Syncope uses a weak PNRG
Details

Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "Maven",
        "name": "org.apache.syncope:syncope"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "1.1.0"
            },
            {
              "fixed": "1.1.8"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2014-3503"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-338"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2023-08-15T22:11:49Z",
    "nvd_published_at": "2014-07-11T14:55:00Z",
    "severity": "MODERATE"
  },
  "details": "Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.",
  "id": "GHSA-4c72-mrhf-23cg",
  "modified": "2023-08-15T22:11:49Z",
  "published": "2022-05-14T02:52:41Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-3503"
    },
    {
      "type": "WEB",
      "url": "https://github.com/apache/syncope/commit/8e0045925a387ee211832c7e0709dd418cda1ad3"
    },
    {
      "type": "WEB",
      "url": "https://syncope.apache.org/security.html#cve-2014-3503-insecure-random-implementations-used-to-generate-p"
    },
    {
      "type": "WEB",
      "url": "https://web.archive.org/web/20140728093808/http://www.securityfocus.com/bid/68431"
    },
    {
      "type": "WEB",
      "url": "https://web.archive.org/web/20201207014021/http://www.securityfocus.com/archive/1/532669/100/0/threaded"
    },
    {
      "type": "WEB",
      "url": "http://packetstormsecurity.com/files/127375/Apache-Syncope-Insecure-Password-Generation.html"
    },
    {
      "type": "WEB",
      "url": "http://svn.apache.org/viewvc?view=revision\u0026revision=r1596537"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [],
  "summary": "Apache Syncope uses a weak PNRG"
}

GHSA-4G94-JFQP-P4F7

Vulnerability from github – Published: 2026-04-13 09:31 – Updated: 2026-04-13 18:30
VLAI
Details

Solstice::Session versions through 1440 for Perl generates session ids insecurely.

The _generateSessionID method returns an MD5 digest seeded by the epoch time, a random hash reference, a call to the built-in rand() function and the process id.

The same method is used in the _generateID method in Solstice::Subsession, which is part of the same distribution.

The epoch time may be guessed, if it is not leaked in the HTTP Date header. Stringified hash refences will contain predictable content. The built-in rand() function is seeded by 16-bits and is unsuitable for security purposes. The process id comes from a small set of numbers.

Predictable session ids could allow an attacker to gain access to systems.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-5085"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-338"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-04-13T07:16:50Z",
    "severity": "CRITICAL"
  },
  "details": "Solstice::Session versions through 1440 for Perl generates session ids insecurely.\n\nThe _generateSessionID method returns an MD5 digest seeded by the epoch time, a random hash reference, a call to the built-in rand() function and the process id.\n\nThe same method is used in the _generateID method in Solstice::Subsession, which is part of the same distribution.\n\nThe epoch time may be guessed, if it is not leaked in the HTTP Date header. Stringified hash refences will contain predictable content. The built-in rand() function is seeded by 16-bits and is unsuitable for security purposes. The process id comes from a small set of numbers.\n\nPredictable session ids could allow an attacker to gain access to systems.",
  "id": "GHSA-4g94-jfqp-p4f7",
  "modified": "2026-04-13T18:30:39Z",
  "published": "2026-04-13T09:31:33Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5085"
    },
    {
      "type": "WEB",
      "url": "https://metacpan.org/dist/Solstice/source/lib/Solstice/Session.pm#L481"
    },
    {
      "type": "WEB",
      "url": "https://metacpan.org/dist/Solstice/source/lib/Solstice/Subsession.pm#L105"
    },
    {
      "type": "WEB",
      "url": "https://security.metacpan.org/docs/guides/random-data-for-security.html"
    },
    {
      "type": "WEB",
      "url": "http://www.openwall.com/lists/oss-security/2026/04/13/2"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-4XRG-5554-QFFR

Vulnerability from github – Published: 2022-05-01 23:28 – Updated: 2025-04-09 03:54
VLAI
Details

OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guessing attacks against cryptographic keys.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2008-0166"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-338"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2008-05-13T17:20:00Z",
    "severity": "HIGH"
  },
  "details": "OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guessing attacks against cryptographic keys.",
  "id": "GHSA-4xrg-5554-qffr",
  "modified": "2025-04-09T03:54:26Z",
  "published": "2022-05-01T23:28:06Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2008-0166"
    },
    {
      "type": "WEB",
      "url": "https://16years.secvuln.info"
    },
    {
      "type": "WEB",
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/42375"
    },
    {
      "type": "WEB",
      "url": "https://news.ycombinator.com/item?id=40333169"
    },
    {
      "type": "WEB",
      "url": "https://www.exploit-db.com/exploits/5622"
    },
    {
      "type": "WEB",
      "url": "https://www.exploit-db.com/exploits/5632"
    },
    {
      "type": "WEB",
      "url": "https://www.exploit-db.com/exploits/5720"
    },
    {
      "type": "WEB",
      "url": "http://metasploit.com/users/hdm/tools/debian-openssl"
    },
    {
      "type": "WEB",
      "url": "http://secunia.com/advisories/30136"
    },
    {
      "type": "WEB",
      "url": "http://secunia.com/advisories/30220"
    },
    {
      "type": "WEB",
      "url": "http://secunia.com/advisories/30221"
    },
    {
      "type": "WEB",
      "url": "http://secunia.com/advisories/30231"
    },
    {
      "type": "WEB",
      "url": "http://secunia.com/advisories/30239"
    },
    {
      "type": "WEB",
      "url": "http://secunia.com/advisories/30249"
    },
    {
      "type": "WEB",
      "url": "http://sourceforge.net/mailarchive/forum.php?thread_name=48367252.7070603%40shemesh.biz\u0026forum_name=rsyncrypto-devel"
    },
    {
      "type": "WEB",
      "url": "http://www.debian.org/security/2008/dsa-1571"
    },
    {
      "type": "WEB",
      "url": "http://www.debian.org/security/2008/dsa-1576"
    },
    {
      "type": "WEB",
      "url": "http://www.kb.cert.org/vuls/id/925211"
    },
    {
      "type": "WEB",
      "url": "http://www.securityfocus.com/archive/1/492112/100/0/threaded"
    },
    {
      "type": "WEB",
      "url": "http://www.securityfocus.com/bid/29179"
    },
    {
      "type": "WEB",
      "url": "http://www.securitytracker.com/id?1020017"
    },
    {
      "type": "WEB",
      "url": "http://www.ubuntu.com/usn/usn-612-1"
    },
    {
      "type": "WEB",
      "url": "http://www.ubuntu.com/usn/usn-612-2"
    },
    {
      "type": "WEB",
      "url": "http://www.ubuntu.com/usn/usn-612-3"
    },
    {
      "type": "WEB",
      "url": "http://www.ubuntu.com/usn/usn-612-4"
    },
    {
      "type": "WEB",
      "url": "http://www.ubuntu.com/usn/usn-612-7"
    },
    {
      "type": "WEB",
      "url": "http://www.us-cert.gov/cas/techalerts/TA08-137A.html"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-54MG-VGRP-MWX9

Vulnerability from github – Published: 2019-05-14 04:01 – Updated: 2021-08-04 15:01
VLAI
Summary
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Ratpack
Details

Ratpack versions before 1.6.1 generate a session ID using a cryptographically weak PRNG in the JDK's ThreadLocalRandom. This means that if an attacker can determine a small window for the server start time and obtain a session ID value, they can theoretically determine the sequence of session IDs.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "Maven",
        "name": "io.ratpack:ratpack-session"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1.6.1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Maven",
        "name": "io.ratpack:ratpack-java"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1.6.1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Maven",
        "name": "io.ratpack:ratpack-groovy"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1.6.1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2019-11808"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-338"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2019-05-14T03:48:09Z",
    "nvd_published_at": "2019-05-07T07:29:00Z",
    "severity": "LOW"
  },
  "details": "Ratpack versions before 1.6.1 generate a session ID using a cryptographically weak PRNG in the JDK\u0027s ThreadLocalRandom. This means that if an attacker can determine a small window for the server start time and obtain a session ID value, they can theoretically determine the sequence of session IDs.",
  "id": "GHSA-54mg-vgrp-mwx9",
  "modified": "2021-08-04T15:01:30Z",
  "published": "2019-05-14T04:01:37Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-11808"
    },
    {
      "type": "WEB",
      "url": "https://github.com/ratpack/ratpack/issues/1448"
    },
    {
      "type": "WEB",
      "url": "https://github.com/ratpack/ratpack/commit/f2b63eb82dd71194319fd3945f5edf29b8f3a42d"
    },
    {
      "type": "WEB",
      "url": "https://github.com/ratpack/ratpack/releases/tag/v1.6.1"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Ratpack"
}

GHSA-56QJ-X9H6-9389

Vulnerability from github – Published: 2023-10-19 21:30 – Updated: 2024-04-04 08:48
VLAI
Details

An issue found in IXP Data Easy Install 6.6.148840 allows a remote attacker to escalate privileges via insecure PRNG.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2023-27791"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-338"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2023-10-19T20:15:08Z",
    "severity": "HIGH"
  },
  "details": "An issue found in IXP Data Easy Install 6.6.148840 allows a remote attacker to escalate privileges via insecure PRNG.",
  "id": "GHSA-56qj-x9h6-9389",
  "modified": "2024-04-04T08:48:57Z",
  "published": "2023-10-19T21:30:17Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27791"
    },
    {
      "type": "WEB",
      "url": "https://www.bramfitt-tech-labs.com/article/easy-install-cve-issue"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-59J9-QV68-3XX5

Vulnerability from github – Published: 2022-04-23 00:40 – Updated: 2024-04-03 23:49
VLAI
Details

A casting error in Chicken before 4.8.0 on 64-bit platform caused the random number generator to return a constant value. NOTE: the vendor states "This function wasn't used for security purposes (and is advertised as being unsuitable)."

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2012-6124"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-338"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2019-10-31T21:15:00Z",
    "severity": "MODERATE"
  },
  "details": "A casting error in Chicken before 4.8.0 on 64-bit platform caused the random number generator to return a constant value. NOTE: the vendor states \"This function wasn\u0027t used for security purposes (and is advertised as being unsuitable).\"",
  "id": "GHSA-59j9-qv68-3xx5",
  "modified": "2024-04-03T23:49:22Z",
  "published": "2022-04-23T00:40:08Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2012-6124"
    },
    {
      "type": "WEB",
      "url": "https://access.redhat.com/security/cve/cve-2012-6124"
    },
    {
      "type": "WEB",
      "url": "https://lists.nongnu.org/archive/html/chicken-hackers/2012-02/msg00084.html"
    },
    {
      "type": "WEB",
      "url": "https://security-tracker.debian.org/tracker/CVE-2012-6124"
    },
    {
      "type": "WEB",
      "url": "http://www.openwall.com/lists/oss-security/2013/02/08/2"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-5F54-X7J7-36P3

Vulnerability from github – Published: 2022-01-21 00:00 – Updated: 2024-09-16 21:30
VLAI
Details

Telenot CompasX versions prior to 32.0 use a weak seed for random number generation leading to predictable AES keys used in the NFC tags used for authorization of users.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2021-34600"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-335",
      "CWE-338"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2022-01-20T12:15:00Z",
    "severity": "HIGH"
  },
  "details": "Telenot CompasX versions prior to 32.0 use a weak seed for random number generation leading to predictable AES keys used in the NFC tags used for authorization of users.",
  "id": "GHSA-5f54-x7j7-36p3",
  "modified": "2024-09-16T21:30:32Z",
  "published": "2022-01-21T00:00:48Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-34600"
    },
    {
      "type": "WEB",
      "url": "https://www.x41-dsec.de/lab/advisories/x41-2021-003-telenot-complex-insecure-keygen"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-5H96-GCCV-M233

Vulnerability from github – Published: 2024-04-30 21:30 – Updated: 2024-11-04 21:30
VLAI
Details

An issue ingalxe.com Galxe platform 1.0 allows a remote attacker to obtain sensitive information via the Web3 authentication process of Galxe, the signed message lacks a nonce (random number)

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2023-50059"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-338"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2024-04-30T19:15:23Z",
    "severity": "MODERATE"
  },
  "details": "An issue ingalxe.com Galxe platform 1.0 allows a remote attacker to obtain sensitive information via the Web3 authentication process of Galxe, the signed message lacks a nonce (random number)",
  "id": "GHSA-5h96-gccv-m233",
  "modified": "2024-11-04T21:30:26Z",
  "published": "2024-04-30T21:30:31Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50059"
    },
    {
      "type": "WEB",
      "url": "https://galxe.com"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-5J8H-3WVC-37WP

Vulnerability from github – Published: 2022-05-24 17:19 – Updated: 2024-04-04 02:51
VLAI
Details

D-Link DIR-865L Ax 1.20B01 Beta devices have a predictable seed in a Pseudo-Random Number Generator.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2020-13784"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-335",
      "CWE-338"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2020-06-03T17:15:00Z",
    "severity": "HIGH"
  },
  "details": "D-Link DIR-865L Ax 1.20B01 Beta devices have a predictable seed in a Pseudo-Random Number Generator.",
  "id": "GHSA-5j8h-3wvc-37wp",
  "modified": "2024-04-04T02:51:16Z",
  "published": "2022-05-24T17:19:03Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-13784"
    },
    {
      "type": "WEB",
      "url": "https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10174"
    },
    {
      "type": "WEB",
      "url": "https://unit42.paloaltonetworks.com/6-new-d-link-vulnerabilities-found-on-home-routers"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-5JX8-Q4CP-RHH6

Vulnerability from github – Published: 2026-03-23 06:30 – Updated: 2026-07-21 13:42
VLAI
Summary
jsrsasign: Incomplete Comparison Allows DSA Private Key Recovery via Biased Nonce Generation
Details

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect compareTo checks that accept out-of-range candidates and thus bias DSA nonces during signature generation.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "jsrsasign"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "7.0.0"
            },
            {
              "fixed": "11.1.1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-4599"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1023",
      "CWE-338"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-03-30T19:29:39Z",
    "nvd_published_at": "2026-03-23T06:16:21Z",
    "severity": "CRITICAL"
  },
  "details": "Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect compareTo checks that accept out-of-range candidates and thus bias DSA nonces during signature generation.",
  "id": "GHSA-5jx8-q4cp-rhh6",
  "modified": "2026-07-21T13:42:18Z",
  "published": "2026-03-23T06:30:29Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4599"
    },
    {
      "type": "WEB",
      "url": "https://github.com/kjur/jsrsasign/pull/647"
    },
    {
      "type": "WEB",
      "url": "https://github.com/kjur/jsrsasign/commit/ee4b013478366cb16cea9a4bdfb218b6077f83b1"
    },
    {
      "type": "WEB",
      "url": "https://security.snyk.io/vuln/SNYK-JS-JSRSASIGN-15370939"
    },
    {
      "type": "WEB",
      "url": "https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-15812264"
    },
    {
      "type": "WEB",
      "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4599.json"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/kjur/jsrsasign"
    },
    {
      "type": "WEB",
      "url": "https://gist.github.com/Kr0emer/081681818b51605c91945126d74b4f20"
    },
    {
      "type": "WEB",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450207"
    },
    {
      "type": "WEB",
      "url": "https://access.redhat.com/security/cve/CVE-2026-4599"
    },
    {
      "type": "WEB",
      "url": "https://access.redhat.com/errata/RHSA-2026:6926"
    },
    {
      "type": "WEB",
      "url": "https://access.redhat.com/errata/RHSA-2026:6912"
    },
    {
      "type": "WEB",
      "url": "https://access.redhat.com/errata/RHSA-2026:6720"
    },
    {
      "type": "WEB",
      "url": "https://access.redhat.com/errata/RHSA-2026:6568"
    },
    {
      "type": "WEB",
      "url": "https://access.redhat.com/errata/RHSA-2026:19410"
    },
    {
      "type": "WEB",
      "url": "https://access.redhat.com/errata/RHSA-2026:19409"
    },
    {
      "type": "WEB",
      "url": "https://access.redhat.com/errata/RHSA-2026:19375"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "jsrsasign: Incomplete Comparison Allows DSA Private Key Recovery via Biased Nonce Generation"
}

Mitigation
Implementation

Use functions or hardware which use a hardware-based random number generation for all crypto. This is the recommended solution. Use CyptGenRandom on Windows, or hw_rand() on Linux.

No CAPEC attack patterns related to this CWE.