CWE-335: PRNG
The product uses a Pseudo-Random Number Generator (PRNG) but does not correctly manage seeds.
16 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-1579 — Insufficient seeding of random number generator
- CVE-2025-27580 — NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 generates predictable tokens (that de
- CVE-2026-11625 — Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes
- CVE-2026-41564 — CryptX versions before 0.088 for Perl do not reseed the Crypt::PK PRNG state after forking
- CVE-2026-11702 — Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes
- CVE-2025-52578 — Incorrect Usage of Seeds in Pseudo-Random Number Generator (CWE- 335) vulnerability in the High Sec ELM may allow a soph
- CVE-2026-3503 — Fault injection attack with ML-DSA and ML-KEM on ARM
- CVE-2025-24783 — Apache Cocoon: continuations may not be private
Recently published
- CVE-2026-11702 — Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes
- CVE-2026-11625 — Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes
- CVE-2026-41564 — CryptX versions before 0.088 for Perl do not reseed the Crypt::PK PRNG state after forking
- CVE-2026-3503 — Fault injection attack with ML-DSA and ML-KEM on ARM
- CVE-2025-52578 — Incorrect Usage of Seeds in Pseudo-Random Number Generator (CWE- 335) vulnerability in the High Sec ELM may allow a soph
- CVE-2025-27580 — NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 generates predictable tokens (that de
- CVE-2025-24783 — Apache Cocoon: continuations may not be private
- CVE-2024-1579 — Insufficient seeding of random number generator