CVE Database
/

CVE-2026-5086

Back to search

CVE-2026-5086

Published: Apr 13, 2026

Modified: Apr 15, 2026

PUBLISHED

Description

Crypt::SecretBuffer versions before 0.019 for Perl is suseceptible to timing attacks. For example, if Crypt::SecretBuffer was used to store and compare plaintext passwords, then discrepencies in timing could be used to guess the secret password.

VendorProductVersions

NERDVANA

Crypt::SecretBuffer

affected
0 - < 0.019

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now