Threats Tagged 'cwe-331'
View all threats tagged with 'cwe-331'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-331'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-71851: CWE-331: Insufficient Entropy in brix crypto-jsCVE-2026-71851 0 crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded from Math.random(), instead of a cryptographically secure source. This generator was introduced in version 3.1.2-4 and remained present in nearly every 3.x release. Nominal requests for 128 or 256 bits of entropy through this function produce effective search spaces of approximately 2 to the 39th and 2 to the 47th possibilities, small enough to enumerate on commodity hardware. Downstream wallet applications that used CryptoJS.lib.WordArray.random() as the entropy source for BIP39 recovery phrases are affected, and an attacker who enumerates the reduced output space can recover the resulting private keys and control the associated funds. This issue is fixed in version 4.0.0. Join the discussion | CVE Database V5 | 08/07/2026, 18:48:08 UTC Added: 08/08/2026, 03:26:45 UTC |
CVE-2025-15629: CWE-331 Insufficient entropy in TP-Link Systems Inc. Omada GatewaysCVE-2025-15629 0 A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictable due to insufficient entropy in session key generation. An attacker who successfully intercepts adoption-related communications may be able to recover session encryption keys and decrypt affected communications. Join the discussion | CVE Database V5 | 08/03/2026, 17:50:44 UTC Added: 08/03/2026, 18:33:33 UTC |
CVE-2026-4932: CWE-331 Insufficient Entropy in IBM PowerVM HypervisorCVE-2026-4932 0 IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physical access to the Transparent Memory Encryption (TME) hardware to decrypt encrypted memory due to insufficient cryptographic entropy. Join the discussion | CVE Database V5 | 07/28/2026, 18:09:32 UTC Added: 07/28/2026, 18:22:45 UTC |
CVE-2026-11403: CWE-331 Insufficient entropy in Sonatype Nexus Repository ManagerCVE-2026-11403 0 A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format-specific API key realm (NuGet API Key, Docker Bearer Token, or npm Bearer Token) must be enabled and the targeted user must have an active API key for this vulnerability to be exploitable. Join the discussion | CVE Database V5 | 07/14/2026, 15:28:23 UTC Added: 07/14/2026, 15:48:09 UTC |
Showing 1 to 4 of 4 results