GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets.
The random method creates the challenge text used for the CAPTCHA by sampling characters from an array using Perl's built-in rand function, and generates a (by default) six-character string.
The built-in rand function is unsuitable for security applications because it is predictable and reversible.
Metrics
Affected Vendors & Products
References
History
Thu, 23 Jul 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Burak
Burak gd::securityimage |
|
| Vendors & Products |
Burak
Burak gd::securityimage |
Fri, 17 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 17 Jul 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets. The random method creates the challenge text used for the CAPTCHA by sampling characters from an array using Perl's built-in rand function, and generates a (by default) six-character string. The built-in rand function is unsuitable for security applications because it is predictable and reversible. | |
| Title | GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets | |
| Weaknesses | CWE-338 CWE-804 |
|
| References |
|
Status: PUBLISHED
Assigner: CPANSec
Published: 2026-07-17T12:54:07.177Z
Updated: 2026-07-17T17:29:23.536Z
Reserved: 2026-06-23T18:17:08.243Z
Link: CVE-2026-13082
Updated: 2026-07-17T17:29:03.597Z
No data.
No data.