What is CVE-2026-71851?
CVE-2026-71851 is a vulnerability in the crypto-js JavaScript library prior to version 4.0.0, where the `CryptoJS.lib.WordArray.random()` method uses a predictable pseudorandom number generator seeded by `Math.random()` instead of a cryptographically secure source. Developers using this library must immediately update to version 4.0.0 or later to mitigate the risk.
Azərbaycanca: CVE-2026-71851, JavaScript kriptoqrafiya kitabxanası olan crypto-js-in 4.0.0-dən əvvəlki versiyalarında aşkarlanmış zəiflikdir. `CryptoJS.lib.WordArray.random()` funksiyası kriptoqrafik cəhətdən təhlükəsiz olmayan `Math.random()` mənbəyindən istifadə etdiyi üçün yaradılan təsadüfi dəyərlər proqnozlaşdırıla bilər. Bu kitabxanadan istifadə edən tərtibatçılar dərhal 4.0.0 və ya daha yeni versiyaya yeniləməlidir.
FAQ2
Which library is affected by CVE-2026-71851?
CVE-2026-71851 affects the crypto-js JavaScript cryptography library.
Which version must developers update to in order to fix this vulnerability?
Developers must update to crypto-js version 4.0.0 or later to fix this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.