Common Weakness Enumeration

CWE-338

Allowed

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

Abstraction: Base · Status: Draft

The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.

342 vulnerabilities reference this CWE, most recent first.

GHSA-94WC-GX8C-8825

Vulnerability from github – Published: 2022-07-07 00:00 – Updated: 2022-07-16 00:00
VLAI
Details

OpenVPN Access Server before 2.11 uses a weak random generator used to create user session token for the web portal

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2022-33738"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-338"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2022-07-06T16:15:00Z",
    "severity": "HIGH"
  },
  "details": "OpenVPN Access Server before 2.11 uses a weak random generator used to create user session token for the web portal",
  "id": "GHSA-94wc-gx8c-8825",
  "modified": "2022-07-16T00:00:30Z",
  "published": "2022-07-07T00:00:26Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-33738"
    },
    {
      "type": "WEB",
      "url": "https://openvpn.net/vpn-server-resources/release-notes/#openvpn-access-server-2-11-0"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-97P2-62HQ-G269

Vulnerability from github – Published: 2026-04-30 12:33 – Updated: 2026-04-30 21:30
VLAI
Details

Dancer::Session::Abstract versions through 1.3522 for Perl generates session ids insecurely.

The session id is generated from summing the character codepoints of the absolute pathname with the process id, the epoch time and calls to the built-in rand() function to return a number between 0 and 999-billion, and concatenating that result three times.

The path name might be known or guessed by an attacker, especially for applications known to be written using Dancer with standard installation locations.

The epoch time can be guessed by an attacker, and may be leaked in the HTTP header.

The process id comes from a small set of numbers, and workers may have sequential process ids.

The built-in rand() function is seeded with 32-bits and is considered unsuitable for security applications.

Predictable session ids could allow an attacker to gain access to systems.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-5080"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-338"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-04-30T12:16:24Z",
    "severity": "MODERATE"
  },
  "details": "Dancer::Session::Abstract versions through 1.3522 for Perl generates session ids insecurely.\n\nThe session id is generated from summing the character codepoints of the absolute pathname with the process id, the epoch time and calls to the built-in rand() function to return a number between 0 and 999-billion, and concatenating that result three times.\n\nThe path name might be known or guessed by an attacker, especially for applications known to be written using Dancer with standard installation locations.\n\nThe epoch time can be guessed by an attacker, and may be leaked in the HTTP header.\n\nThe process id comes from a small set of numbers, and workers may have sequential process ids.\n\nThe built-in rand() function is seeded with 32-bits and is considered unsuitable for security applications.\n\nPredictable session ids could allow an attacker to gain access to systems.",
  "id": "GHSA-97p2-62hq-g269",
  "modified": "2026-04-30T21:30:35Z",
  "published": "2026-04-30T12:33:12Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5080"
    },
    {
      "type": "WEB",
      "url": "https://metacpan.org/release/BIGPRESH/Dancer-1.3522/source/lib/Dancer/Session/Abstract.pm#L85-102"
    },
    {
      "type": "WEB",
      "url": "https://security.metacpan.org/patches/D/Dancer/1.3522/CVE-2026-5080-r1.patch"
    },
    {
      "type": "WEB",
      "url": "http://www.openwall.com/lists/oss-security/2026/04/30/19"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-98R5-R223-6XWF

Vulnerability from github – Published: 2026-03-05 03:31 – Updated: 2026-03-05 21:30
VLAI
Details

Net::NSCA::Client versions through 0.009002 for Perl uses a poor random number generator.

Version v0.003 switched to use Data::Rand::Obscure instead of Crypt::Random for generation of a random initialisation vectors.

Data::Rand::Obscure uses Perl's built-in rand() function, which is not suitable for cryptographic functions.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-57854"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-338"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-03-05T03:15:53Z",
    "severity": "CRITICAL"
  },
  "details": "Net::NSCA::Client versions through 0.009002 for Perl uses a poor random number generator.\n\nVersion v0.003 switched to use Data::Rand::Obscure instead of Crypt::Random for generation of a random initialisation vectors.\n\nData::Rand::Obscure uses Perl\u0027s built-in rand() function, which is not suitable for cryptographic functions.",
  "id": "GHSA-98r5-r223-6xwf",
  "modified": "2026-03-05T21:30:38Z",
  "published": "2026-03-05T03:31:26Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57854"
    },
    {
      "type": "WEB",
      "url": "https://metacpan.org/release/DOUGDUDE/Net-NSCA-Client-0.009002/source/lib/Net/NSCA/Client/InitialPacket.pm#L119"
    },
    {
      "type": "WEB",
      "url": "https://patch-diff.githubusercontent.com/raw/dougwilson/perl5-net-nsca-client/pull/2.patch"
    },
    {
      "type": "WEB",
      "url": "http://www.openwall.com/lists/oss-security/2026/03/05/1"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-99F2-VHMM-9FW8

Vulnerability from github – Published: 2025-01-02 06:30 – Updated: 2025-04-08 09:31
VLAI
Details

The Net::EasyTCP package 0.15 through 0.26 for Perl uses Perl's builtin rand() if no strong randomization module is present.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-56830"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-338"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-01-02T05:15:07Z",
    "severity": "MODERATE"
  },
  "details": "The Net::EasyTCP package 0.15 through 0.26 for Perl uses Perl\u0027s builtin rand() if no strong randomization module is present.",
  "id": "GHSA-99f2-vhmm-9fw8",
  "modified": "2025-04-08T09:31:09Z",
  "published": "2025-01-02T06:30:47Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56830"
    },
    {
      "type": "WEB",
      "url": "https://github.com/briandfoy/cpan-security-advisory/issues/184"
    },
    {
      "type": "WEB",
      "url": "https://lists.debian.org/debian-lts-announce/2025/04/msg00015.html"
    },
    {
      "type": "WEB",
      "url": "https://metacpan.org/release/MNAGUIB/EasyTCP-0.26/changes"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-9FP2-68JW-464M

Vulnerability from github – Published: 2022-04-12 00:00 – Updated: 2022-04-16 00:01
VLAI
Details

The Download Manager WordPress plugin before 3.2.39 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or password protections set for the download.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2022-0828"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-326",
      "CWE-338"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2022-04-11T15:15:00Z",
    "severity": "HIGH"
  },
  "details": "The Download Manager WordPress plugin before 3.2.39 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or password protections set for the download.",
  "id": "GHSA-9fp2-68jw-464m",
  "modified": "2022-04-16T00:01:10Z",
  "published": "2022-04-12T00:00:36Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-0828"
    },
    {
      "type": "WEB",
      "url": "https://wpscan.com/vulnerability/7f0742ad-6fd7-4258-9e44-d42e138789bb"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-9GWW-CR64-679C

Vulnerability from github – Published: 2026-02-17 00:30 – Updated: 2026-02-17 15:31
VLAI
Details

Concierge::Sessions versions from 0.8.1 before 0.8.5 for Perl generate insecure session ids. The generate_session_id function in Concierge::Sessions::Base defaults to using the uuidgen command to generate a UUID, with a fallback to using Perl's built-in rand function. Neither of these methods are secure, and attackers are able to guess session_ids that can grant them access to systems. Specifically,

  • There is no warning when uuidgen fails. The software can be quietly using the fallback rand() function with no warnings if the command fails for any reason.
  • The uuidgen command will generate a time-based UUID if the system does not have a high-quality random number source, because the call does not explicitly specify the --random option. Note that the system time is shared in HTTP responses.
  • UUIDs are identifiers whose mere possession grants access, as per RFC 9562.
  • The output of the built-in rand() function is predictable and unsuitable for security applications.
Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-2439"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-338"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-02-16T22:22:41Z",
    "severity": "CRITICAL"
  },
  "details": "Concierge::Sessions versions from 0.8.1 before 0.8.5 for Perl generate insecure session ids. The generate_session_id function in Concierge::Sessions::Base defaults to using the uuidgen command to generate a UUID, with a fallback to using Perl\u0027s built-in rand function. Neither of these methods are secure, and attackers are able to guess session_ids that can grant them access to systems. Specifically,\n\n  *  There is no warning when uuidgen fails. The software can be quietly using the fallback rand() function with no warnings if the command fails for any reason.\n  *  The uuidgen command will generate a time-based UUID if the system does not have a high-quality random number source, because the call does not explicitly specify the --random option. Note that the system time is shared in HTTP responses.\n  *  UUIDs are identifiers whose mere possession grants access, as per RFC 9562.\n  *  The output of the built-in rand() function is predictable and unsuitable for security applications.",
  "id": "GHSA-9gww-cr64-679c",
  "modified": "2026-02-17T15:31:35Z",
  "published": "2026-02-17T00:30:18Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2439"
    },
    {
      "type": "WEB",
      "url": "https://github.com/bwva/Concierge-Sessions/commit/20bb28e92e8fba307c4ff8264701c215be65e73b"
    },
    {
      "type": "WEB",
      "url": "https://metacpan.org/release/BVA/Concierge-Sessions-v0.8.4/diff/BVA/Concierge-Sessions-v0.8.5#lib/Concierge/Sessions/Base.pm"
    },
    {
      "type": "WEB",
      "url": "https://perldoc.perl.org/5.42.0/functions/rand"
    },
    {
      "type": "WEB",
      "url": "https://security.metacpan.org/docs/guides/random-data-for-security.html"
    },
    {
      "type": "WEB",
      "url": "https://www.rfc-editor.org/rfc/rfc9562.html#name-security-considerations"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-9PW3-X84F-XCWF

Vulnerability from github – Published: 2026-08-05 21:31 – Updated: 2026-10-05 22:31
Withdrawn 2026-10-05 VLAI
Summary
Duplicate Advisory: Langflow: Weak Fernet Key via random.seed()
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-jxw3-mjmx-3pqm. This link is maintained to preserve external references.

Original Description

IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "PyPI",
        "name": "langflow"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "last_affected": "1.10.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [],
  "database_specific": {
    "cwe_ids": [
      "CWE-338"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-05T22:31:30Z",
    "nvd_published_at": "2026-08-05T19:17:49Z",
    "severity": "HIGH"
  },
  "details": "## Duplicate Advisory\n\nThis advisory has been withdrawn because it is a duplicate of\u00a0GHSA-jxw3-mjmx-3pqm. This link is maintained to preserve external references.\n\n## Original Description\nIBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the\u00a0ensure_fernet_key() function.",
  "id": "GHSA-9pw3-x84f-xcwf",
  "modified": "2026-10-05T22:31:30Z",
  "published": "2026-08-05T21:31:38Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9205"
    },
    {
      "type": "WEB",
      "url": "https://github.com/langflow-ai/langflow/pull/13704"
    },
    {
      "type": "WEB",
      "url": "https://github.com/langflow-ai/langflow/commit/094694d3f20c1da499f4d8dbac15c510609e3026"
    },
    {
      "type": "WEB",
      "url": "https://www.ibm.com/support/pages/node/7282648"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Duplicate Advisory: Langflow: Weak Fernet Key via random.seed()",
  "withdrawn": "2026-10-05T22:31:30Z"
}

GHSA-9Q2F-7HM7-62H6

Vulnerability from github – Published: 2022-09-19 00:00 – Updated: 2022-09-22 00:00
VLAI
Details

profanity through 1.60 has only four billion possible RNG initializations. Thus, attackers can recover private keys from Ethereum vanity addresses and steal cryptocurrency, as exploited in the wild in June 2022.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2022-40769"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-338"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2022-09-18T17:15:00Z",
    "severity": "HIGH"
  },
  "details": "profanity through 1.60 has only four billion possible RNG initializations. Thus, attackers can recover private keys from Ethereum vanity addresses and steal cryptocurrency, as exploited in the wild in June 2022.",
  "id": "GHSA-9q2f-7hm7-62h6",
  "modified": "2022-09-22T00:00:30Z",
  "published": "2022-09-19T00:00:28Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40769"
    },
    {
      "type": "WEB",
      "url": "https://github.com/johguse/profanity/issues/61"
    },
    {
      "type": "WEB",
      "url": "https://blog.1inch.io/a-vulnerability-disclosed-in-profanity-an-ethereum-vanity-address-tool-68ed7455fc8c"
    },
    {
      "type": "WEB",
      "url": "https://github.com/johguse/profanity"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-9Q3X-J473-5399

Vulnerability from github – Published: 2026-09-16 21:32 – Updated: 2026-09-16 21:32
VLAI
Details

SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math/rand generator, allowing attackers to reconstruct the key offline. Unauthenticated remote attackers who can bound the install timestamp can regenerate the secret and forge valid administrator session cookies to gain control of protected sites.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-92749"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-338"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-09-16T21:17:23Z",
    "severity": "CRITICAL"
  },
  "details": "SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math/rand generator, allowing attackers to reconstruct the key offline. Unauthenticated remote attackers who can bound the install timestamp can regenerate the secret and forge valid administrator session cookies to gain control of protected sites.",
  "id": "GHSA-9q3x-j473-5399",
  "modified": "2026-09-16T21:32:52Z",
  "published": "2026-09-16T21:32:52Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92749"
    },
    {
      "type": "WEB",
      "url": "https://github.com/chaitin/SafeLine/issues/1298"
    },
    {
      "type": "WEB",
      "url": "https://github.com/chaitin/SafeLine"
    },
    {
      "type": "WEB",
      "url": "https://github.com/chaitin/SafeLine/blob/v9.4.1/management/webserver/model/option.go#L27"
    },
    {
      "type": "WEB",
      "url": "https://github.com/chaitin/SafeLine/blob/v9.4.1/management/webserver/utils/random.go#L10-L17"
    },
    {
      "type": "WEB",
      "url": "https://www.vulncheck.com/advisories/safeline-through-9.4.1-authentication-bypass-via-weak-session-secret"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ]
}

GHSA-9QFG-3VC9-GP3W

Vulnerability from github – Published: 2022-05-24 17:34 – Updated: 2022-05-24 17:34
VLAI
Details

In InfiniteWP Admin Panel before 3.1.12.3, resetPasswordSendMail generates a weak password-reset code, which makes it easier for remote attackers to conduct admin Account Takeover attacks.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2020-28642"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-338"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2020-11-16T02:15:00Z",
    "severity": "CRITICAL"
  },
  "details": "In InfiniteWP Admin Panel before 3.1.12.3, resetPasswordSendMail generates a weak password-reset code, which makes it easier for remote attackers to conduct admin Account Takeover attacks.",
  "id": "GHSA-9qfg-3vc9-gp3w",
  "modified": "2022-05-24T17:34:20Z",
  "published": "2022-05-24T17:34:20Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-28642"
    },
    {
      "type": "WEB",
      "url": "https://www.whitehack.de/advisories/HWADV2020-001.txt"
    }
  ],
  "schema_version": "1.4.0",
  "severity": []
}

Mitigation
Implementation

Use functions or hardware which use a hardware-based random number generation for all crypto. This is the recommended solution. Use CyptGenRandom on Windows, or hw_rand() on Linux.

No CAPEC attack patterns related to this CWE.