CVE-2026-5086: Nerdvana Crypt::secretbuffer
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Crypt::SecretBuffer versions before 0.019 for Perl is suseceptible to timing attacks. For example, if Crypt::SecretBuffer was used to store and compare plaintext passwords, then discrepencies in timing could be used to guess the secret password.
Affected products
- Nerdvana Crypt::secretbuffer: before 0.019 (fixed in 0.019)
Published 2026-04-13. Last modified 2026-06-17.