Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-86411.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-86411
Upstream
Published
2026-05-08T18:16:34Z
Modified
2026-08-30T05:24:52Z
Summary
CVE-2026-6659 affecting package perl-Crypt-PasswdMD5 1.4.0-19
Details

Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts.

The built-in rand function is predictable, and unsuitable for cryptography.

References

Affected packages

Azure Linux:3 / perl-Crypt-PasswdMD5

Package

Name
perl-Crypt-PasswdMD5
Purl
pkg:rpm/azure-linux/perl-Crypt-PasswdMD5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.4.0-19

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-86411.json"