VDB
GCVE-110-MAGEIA-2025-62
GCVE-110-MAGEIA-2025-62
Advisory Published
In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl,
the default nonce is a 32-bit integer generated from the built-in rand()
function, which is not cryptographically strong. (CVE-2025-22376)
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | perl-Net-OAuth | 0.300.0-1.mga9 (unaffected), 0 (affected), 0 (affected), 0.300.0-1.mga9 (unaffected) | — |
| Mageia | mesa | 0 (affected), 25.0.7-4.mga9.tainted (unaffected), 25.0.7-4.mga9 (unaffected), 0 (affected) | — |
| Mageia | perl-Crypt-URandom | 0 (affected), 0.370.0-1.mga9 (unaffected), 0 (affected), 0.370.0-1.mga9 (unaffected) | — |
| Mageia | perl-Module-Build | 0 (affected), 0.423.400-1.mga9 (unaffected), 0.423.400-1.mga9 (unaffected), 0 (affected) | — |
Aliases
References
Updated perl-Net-OAuth, perl-Crypt-URandom & perl-Module-Build packages fix security vulnerability
advisory
Updated perl-Net-OAuth, perl-Crypt-URandom & perl-Module-Build packages fix security vulnerability
issue
Updated perl-Net-OAuth, perl-Crypt-URandom & perl-Module-Build packages fix security vulnerability
issue
Updated mesa packages fix bug
advisory
Browse GCVE Records
73,873 records in the GCVE database · Updated July 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.