CVE-2026-5088 affects Apache::API::Password in the Apache2-API Perl distribution through version 0.5.2, where password salt generation can fall back to Perl’s built-in rand function if Crypt::URandom or Bytes::Random::Secure is unavailable. The vulnerable _make_salt and _make_salt_bcrypt methods may therefore produce weak, predictable salt values for password hashing, exposing deployments to reduced password protection and fitting CWE-338, use of a cryptographically weak pseudo-random number generator.
The issue was disclosed by the CPAN Security Group, and maintainer Jacques Deguest said it was fixed in version 0.5.3, which was released to CPAN. Organizations using the module are advised to upgrade to 0.5.3 or later and ensure Crypt::URandom is installed to prevent insecure fallback behavior during salt generation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
On April 15, 2026, the CPAN Security Group disclosed that Apache::API::Password through version 0.5.2 could generate weak, predictable password salts when Crypt::URandom or Bytes::Random::Secure were unavailable. The issue was classified as CWE-338, and users were advised to upgrade to version 0.5.3 or later and install Crypt::URandom.
Maintainer Jacques Deguest fixed CVE-2026-5088 in Apache::API::Password version 0.5.3 and released it on CPAN the morning of April 15, 2026. The update removes the insecure fallback to Perl's built-in rand function for generating password salts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.