Security Advisory

CVE-2026-6656

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-20 07:01:45
Last updated 2026-07-20 18:38:21
Assigner CPANSec
CVSS score not scored
State PUBLISHED

Description

Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the built-in eq operator. This allows discrepancies in timing to be used to guess the underlying hash.