CVE-2026-5086 PUBLISHED

Crypt::SecretBuffer versions before 0.019 for Perl is suseceptible to timing attacks

Assigner: CPANSec
Reserved: 28.03.2026 Published: 13.04.2026 Updated: 14.04.2026

Crypt::SecretBuffer versions before 0.019 for Perl is suseceptible to timing attacks.

For example, if Crypt::SecretBuffer was used to store and compare plaintext passwords, then discrepencies in timing could be used to guess the secret password.

Product Status

Vendor NERDVANA
Product Crypt::SecretBuffer
Versions Default: unaffected
  • affected from 0 to 0.019 (excl.)

Solutions

Upgrade to version 0.019 or later.

References

Problem Types

  • CWE-208 Observable Timing Discrepancy CWE