CVE-2024-57854: Dougdude Net::nsca::client
Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Net::NSCA::Client versions through 0.009002 for Perl uses a poor random number generator. Version v0.003 switched to use Data::Rand::Obscure instead of Crypt::Random for generation of a random initialisation vectors. Data::Rand::Obscure uses Perl's built-in rand() function, which is not suitable for cryptographic functions.
Affected products
- Dougdude Net::nsca::client: up to and including 0.009002
Published 2026-03-05. Last modified 2026-06-17.