CVE-2026-5086 Details
Description
Crypt::SecretBuffer versions before 0.019 for Perl is suseceptible to timing attacks. For example, if Crypt::SecretBuffer was used to store and compare plaintext passwords, then discrepencies in timing could be used to guess the secret password.
A timing attack vulnerability exists in Crypt::SecretBuffer versions prior to 0.019 for Perl. This issue allows an attacker to exploit discrepancies in timing when the module is used to store and compare plaintext passwords, potentially leading to the guessing of secret passwords.
Users can upgrade to Crypt::SecretBuffer version 0.019 or later, where this vulnerability has been addressed. Instructions for downloading the latest version are available on MetaCPAN.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://metacpan.org/release/NERDVANA/Crypt-SecretBuffer-0.019/source/Changes | CPANSec | ProductRelease Notes |
| http://www.openwall.com/lists/oss-security/2026/04/13/12 | CVE | Mailing ListThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-208 | Observable Timing Discrepancy | CPANSec |
Affected Products
| Product | Versions |
|---|---|
| nerdvana crypt::secretbuffer | < 0.019 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CPANSec |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 6, 2026 | Initial Analysis | [email protected] |
| Apr 15, 2026 | CVE Modified | CISA-ADP |
| Apr 14, 2026 | CVE Modified | CVE |
| Apr 13, 2026 | New CVE Received | CPANSec |