Uses java.util.Random() which is not cryptographically secure.
If an attacker can predict the random delays, they may still be able to perform timing attacks.
Jervis will use SecureRandom for timing randomization.
Upgrade to Jervis 2.2.
None
{
"cwe_ids": [
"CWE-330"
],
"github_reviewed": true,
"github_reviewed_at": "2026-01-13T14:55:35Z",
"nvd_published_at": "2026-01-13T20:16:07Z",
"severity": "HIGH"
}