CVE-2018-25107

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

The Crypt::Random::Source package before 0.13 for Perl has a fallback to the built-in rand() function, which is not a secure source of random bits.

Published 2024-12-29. Last modified 2026-06-17.