CVE-2026-5086: Nerdvana Crypt::secretbuffer

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Crypt::SecretBuffer versions before 0.019 for Perl is suseceptible to timing attacks. For example, if Crypt::SecretBuffer was used to store and compare plaintext passwords, then discrepencies in timing could be used to guess the secret password.

Affected products

  • Nerdvana Crypt::secretbuffer: before 0.019 (fixed in 0.019)

Published 2026-04-13. Last modified 2026-06-17.