Security Advisory

CVE-2026-5086

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-04-13 22:54:53
Last updated 2026-04-15 20:03:28
Assigner CPANSec
CVSS score not scored
State PUBLISHED

Description

Crypt::SecretBuffer versions before 0.019 for Perl is suseceptible to timing attacks. For example, if Crypt::SecretBuffer was used to store and compare plaintext passwords, then discrepencies in timing could be used to guess the secret password.