What is CVE-2026-18536?
CVE-2026-18536 affects Data::Entropy for Perl versions before 0.010, which fetch remote entropy sources over plain HTTP. This flaw allows potential interception or tampering with entropy data from sources like RandomOrg and RandomnumbersInfo, compromising cryptographic security. Users should upgrade to version 0.010 or later to enforce secure connections.
Azərbaycanca: CVE-2026-18536 Perl üçün Data::Entropy modulunun 0.010 versiyasından əvvəlki versiyalarında aşkar edilib. Bu boşluq uzaq entropiya mənbələrinə (RandomOrg, RandomnumbersInfo) düz HTTP üzərindən müraciət edir, bu isə şəbəkə üzərindən entropiya məlumatlarının ələ keçirilməsi və manipulyasiyası riskini yaradır. Tərtibatçılar modulu ən azı 0.010 versiyasına yeniləməli və ya alternativ təhlükəsiz entropiya mənbələrindən istifadə etməlidir.
FAQ2
Which Perl module is affected by CVE-2026-18536?
This vulnerability affects the Data::Entropy module for Perl in versions prior to 0.010.
What is the root cause of CVE-2026-18536?
The root cause is that the module fetches remote entropy sources over plain HTTP, creating a risk of interception or tampering with the entropy data.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.