CPANSA-Bytes-Random-Secure-Tiny-2026-11702: Bytes-Random-Secure-Tiny vulnerability
| Publisher | giterlizzi | Document category | csaf_security_advisory |
|---|---|---|---|
| Initial release date | 2026-06-26T00:00:00 | Engine | CSAF Perl Toolkit 0.26 |
| Current release date | 2026-06-26T00:00:00 | Build Date | |
| Current version | 1 | Status | final |
| CVSS v3.1 Base Score | 7.5 | Severity | |
| Original language | Language | en | |
| Also referred to | |||
Vulnerability Description
Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes. When an object is initialised before forking, then the internal state for the PRNG is shared across processes and identical random streams will be produced. Secrets generated in multiprocess applications are predictable across processes.
Vulnerabilities
CVE-2026-11702
Vulnerability DescriptionBytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes.
When an object is initialised before forking, then the internal state for the PRNG is shared across processes and identical random streams will be produced.
Secrets generated in multiprocess applications are predictable across processes.
| Weakness | CWE-335 : Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) |
|---|
Product status
Known affected
| Product | Score | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Bytes-Random-Secure-Tiny greater than 0 |
|
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-Bytes-Random-Secure-Tiny-2026-11702 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2026/cpansa-bytes-random-secure-tiny-2026-11702.json - https://github.com/daoswald/Bytes-Random-Secure-Tiny/issues/6 external
https://github.com/daoswald/Bytes-Random-Secure-Tiny/issues/6 - https://github.com/daoswald/Bytes-Random-Secure-Tiny/pull/7 external
https://github.com/daoswald/Bytes-Random-Secure-Tiny/pull/7 - https://security.metacpan.org/patches/B/Bytes-Random-Secure-Tiny/1.011/CVE-2026-11702-r1.patch external
https://security.metacpan.org/patches/B/Bytes-Random-Secure-Tiny/1.011/CVE-2026-11702-r1.patch - https://www.cve.org/CVERecord?id=CVE-2026-11625 external
https://www.cve.org/CVERecord?id=CVE-2026-11625 - https://www.cve.org/CVERecord?id=CVE-2026-41564 external
https://www.cve.org/CVERecord?id=CVE-2026-41564 - CVE-2026-11702 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2026-11702
Revision history
| Version | Date of the revision | Summary of the revision |
|---|---|---|
| 1 | Fri Jun 26 00:00:00 2026 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/