CWE-331: Insufficient Entropy
The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.
83 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-47781 — Rallly Insufficient Password Login Token Entropy Leads to Account Takeover
- CVE-2025-52464 — Meshtastic Repeated Public and Private Keypairs
- CVE-2024-36400 — nano-id is unable to generate the correct character set
- CVE-2025-66565 — Fiber Utils UUIDv4 and UUID Silent Fallback to Predictable Values
- CVE-2025-67504 — WBCE CMS has Weak Random Number Generator in Password Generation Function
- CVE-2025-50122 — A CWE-331: Insufficient Entropy vulnerability exists that could cause root password discovery when the password generati
- CVE-2025-15387 — QNO Technology|VPN Firewall - Insufficient Entropy
- CVE-2026-22698 — RustCrypto SM2-PKE has 32-bit Biased Nonce Vulnerability
- CVE-2026-7210 — The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection
- CVE-2026-42155 — Magento LTS: Weak API Session ID — Predictable MD5 of Time-Derived Inputs
- CVE-2025-13399 — Insecure Encryption in Communication with the Web Interface on TP-Link VX800v
- CVE-2026-62646 — A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A session identifier is generated using an
- CVE-2026-71851 — crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
- CVE-2026-4827 — Insufficient Entropy vulnerability on Multiple Products
- CVE-2026-2336 — Weak webstax_auth Cookie Authentication Allows Privilege Escalation
- CVE-2026-11403 — Nexus Repository Manager - Insufficient Entropy in Format-Specific API Key Generation
- CVE-2025-14261 — Lack of entropy allows registered low-privileged users of Litmus to crack valid JWT tokens and gain admin privileges
- CVE-2025-54885 — Thinbus generates insufficient entropy: 252 bits vs minimum 256 bits
- CVE-2026-1814 — Rapid7 Nexpose Insecure Java Keystore Password Generation
- CVE-2024-22473 — Uninitialized TRNG used for ECDSA after EM2/EM3 sleep for VSE devices
Recently published
- CVE-2026-80171 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-62646 — A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A session identifier is generated using an
- CVE-2026-27490 — Combodo iTop: Weak secret generation for inline image
- CVE-2026-4936 — Power System Insufficient Entropy
- CVE-2026-4937 — Power System Insufficient Entropy
- CVE-2026-19906 — pkp pkp-lib API Key Generation APIProfileForm.php setData entropy
- CVE-2026-19748 — Tenda CH7 Kylin Web Service CWebSessionManager_ParseSession entropy
- CVE-2026-71851 — crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
- CVE-2025-15629 — Weak Session Key Generation in TP-Link Omada Adoption Protocol
- CVE-2026-4932 — This Power System update is being released to address Insufficient Entropy
- CVE-2026-11403 — Nexus Repository Manager - Insufficient Entropy in Format-Specific API Key Generation
- CVE-2026-13199 — Insufficient Entropy in Raspberry Pi 5 and Compute Module 5
- CVE-2026-4930 — DPA Countermeasures weakening on Series 3 devices
- CVE-2026-46473 — Authen::TOTP versions before 0.1.1 for Perl generate secrets using rand
- CVE-2026-8700 — Crypt::DSA versions before 1.20 for Perl generate seeds using rand
- CVE-2026-46474 — Trog::TOTP versions before 1.006 for Perl generate secrets using rand
- CVE-2026-42155 — Magento LTS: Weak API Session ID — Predictable MD5 of Time-Derived Inputs
- CVE-2025-14972 — Insufficient DPA countermeasure reseeding
- CVE-2026-4827 — Insufficient Entropy vulnerability on Multiple Products
- CVE-2026-7210 — The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection