CVE-2026-18536

HIGH CVSS 3.1: 7.5 EPSS 0.16%
Updated Aug 07, 2026
Rrwo
Parameter Value
CVSS 7.5 (HIGH)
Affected Versions before 0.010
Fixed In 0.010
Type CWE-319 (Cleartext Transmission), CWE-353
Vendor Rrwo
Public PoC No

Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource::RandomOrg and Data::Entropy::RawSource::RandomnumbersInfo remote sources are accessed over plain HTTP. The Data::Entropy::RawSource::RandomOrg integrity check trivially matches any non-empty byte string.

Any on-path attacker, such as open WiFi, a compromised ISP, captive portal, or a hostile egress proxy substitutes the response and thereby chooses the bytes returned by rand_bits and rand_int for every application that selected one of these sources via with_entropy_source. The _checkbuf method response is equally attacker-controlled, so the retry/sleep behaviour is steerable too.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Rrwo Data\
cpe:2.3:a:rrwo:data\:\:entropy:*:*:*:*:*:perl:*:*
0.010