CVE-2026-5082
Amon2::Plugin::Web::CSRFDefender versions from 7.00 through 7.03 for Perl generate an insecure session id. The generate_session_id function will attempt to read bytes from the /dev/urandom device, but if that is unavailable then it generates bytes using SHA-1 hash seeded with the built-in rand() function, the PID, and the high resolution epoch time. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage. Amon2::Plugin::Web::CSRFDefender versions before 7.00 were part of Amon2, which was vulnerable to insecure session ids due to CVE-2025-15604. Note that the author has deprecated this module.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS probability
- 0.40%
- CWE
- CWE-340, CWE-338
- Published
- 2026-04-08
- Last modified
- 2026-04-08
Affected products
- TOKUHIROM Amon2::Plugin::Web::CSRFDefender
Weakness type
Related vulnerabilities
- CVE-2026-64964 — Generation of Predictable Email Confirmation Token in ATutor
- CVE-2025-14602 — Weak File Name Generation in vsDesk
- CVE-2026-75106 — OpnForm Editable Submission Secret Derivation via Empty Hashids Salt
- CVE-2026-13577 — Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable
- CVE-2026-47085 — An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can...
- CVE-2026-56016 — CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources
- CVE-2026-9219 — Setracker2 Children's Smartwatch Ecosystem Generation of Predictable Numbers or Identifiers
- CVE-2026-11374 — Account Takeover via Predictable SSO Ticket Generation