CVE-2025-22376

Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.

In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, the default nonce is a 32-bit integer generated from the built-in rand() function, which is not cryptographically strong.

Published 2025-01-03. Last modified 2026-06-17.