CVE-2024-57854: Dougdude Net::nsca::client

Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Net::NSCA::Client versions through 0.009002 for Perl uses a poor random number generator. Version v0.003 switched to use Data::Rand::Obscure instead of Crypt::Random for generation of a random initialisation vectors. Data::Rand::Obscure uses Perl's built-in rand() function, which is not suitable for cryptographic functions.

Affected products

  • Dougdude Net::nsca::client: up to and including 0.009002

Published 2026-03-05. Last modified 2026-06-17.