Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-338'

View all threats tagged with 'cwe-338'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-338

Threats Tagged 'cwe-338'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-9733: CWE-340 Generation of Predictable Numbers or Identifiers in HAYAJO Mojolicious::Plugin::Web::Auth::OAuth2CVE-2026-9733
0

Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no state generator is specified in the constructor, the module defaults to using a SHA-1 hash of predictable and low-entropy sources, including the epoch time (which is leaked via the HTTP Date header) and a call to Perl's built-in rand function. A predictable state allows an attacker to hijack another user's session through cross site request forgery (CSRF).

Join the discussion
CVE-2026-56141: CWE-338 in JetBrains HubCVE-2026-56141
0

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable restore codes was possible

Join the discussion
CVE-2026-9692: CWE-340 Generation of Predictable Numbers or Identifiers in HAYAJO Mojolicious::Sessions::StorableCVE-2026-9692
0

Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, the heap address of an anonymous hash, and the PID. These are predictable or low-entropy sources that are unsuitable for security purposes.

Join the discussion
CVE-2026-11832: CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in BIAFRA Dancer2::Plugin::Auth::OAuthCVE-2026-11832
0

Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl use a predictable nonce generated by hashing the epoch time with MD5, which is a cryptographically weak pseudo-random number generator. This vulnerability (CVE-2026-11832) can lead to compromised confidentiality and integrity of authentication tokens. The CVSS score is 9.1, indicating a critical severity level. No official patch or remediation guidance is currently provided by the vendor.

Join the discussion
CVE-2026-9638: CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in ARODLAND Crypt::PBKDF2CVE-2026-9638
0

Crypt::PBKDF2 versions before 0.261630 for Perl use a cryptographically weak pseudo-random number generator for salt generation. Specifically, these versions rely on the built-in rand function, which is predictable and unsuitable for cryptographic purposes. This weakness can compromise the security of derived keys by making salts guessable.

Join the discussion
CVE-2026-46493: CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in haxtheweb haxcms-phpCVE-2026-46493
0

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.1 use `uniqid` for generating salts, which is unsuitable. Version 26.0.1 fixes the issue.

Join the discussion
CVE-2026-11347: CWE-321: Use of Hard-coded Cryptographic Key in linqi GmbH linqiCVE-2026-11347
0

The linqi application contains hardcoded cryptographic keys. Additionally, the application uses a weak algorithm with a limited ASCII charset to dynamically generate Initialization Vectors (IVs) for AES/CBC encryption, making known-plaintext attacks feasible. An attacker with local access can leverage these vulnerabilities to decrypt sensitive obfuscated strings, including ConnectionString values containing database credentials from appsettings.json.

Join the discussion
CVE-2026-41858: CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Cloud Foundry Foundation windows-utilities-releaseCVE-2026-41858
0

Weak Randomness / Insecure Cryptographic Primitive (CWE-338) in Get-RandomPassword in BOSH-Ecosystem / windows-utilities-release allows a network attacker to estimate VM boot time and reconstruct a small candidate list to recover the Administrator password. The randomize_password job exists solely to lock the local Administrator account behind an unguessable password as a hardening control. Because the password is derived from a predictable, clock-seeded PRNG, a network attacker who can estimate VM boot time can reconstruct a small candidate list and recover the Administrator password, defeating the hardening control. Affected versions: - windows-utilities-release: all versions prior to v0.23.0 (inclusive); fixed in v0.23.0 or later

Join the discussion
CVE-2026-8647: CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator in MIK Crypt::ScryptKDFCVE-2026-8647
0

CVE-2026-8647 is a medium severity vulnerability in the Perl module Crypt::ScryptKDF versions through 0.010. The module uses an insecure random number source when no cryptographically secure pseudo-random number generator (CSPRNG) module is available. Specifically, the random_bytes function falls back to the built-in rand() function, which is not cryptographically secure. This weakness can reduce the effectiveness of cryptographic operations relying on this module.

Join the discussion

Showing 1 to 9 of 9 results

Filters:Tag: cwe-338
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses