CVE Explorer
CVE-2026-16615
A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAut
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
affected · 2 assertions
{"collectionURL":"https://gitlab.gnome.org/GNOME/librest","defaultStatus":"affected","packageName":"librest","product":"librest","vendor":"GNOME"}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:e2571bce33877c1f1544a76890c4dbf19e677c34d8b1d6fb42e4fee58a17e608 · sha256:ff1231e860e0db1d… · /containers/cna/affected/0
{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"defaultStatus":"affected","packageName":"rest","product":"Red Hat Enterprise Linux 10","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"0:0.9.1-11.el10_2.1","versionType":"rpm"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:e2571bce33877c1f1544a76890c4dbf19e677c34d8b1d6fb42e4fee58a17e608 · sha256:ff1231e860e0db1d… · /containers/cna/affected/1
Affected products and versions
2 source assertions{"collectionURL":"https://gitlab.gnome.org/GNOME/librest","defaultStatus":"affected","packageName":"librest","product":"librest","vendor":"GNOME"}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:e2571bce33877c1f1544a76890c4dbf19e677c34d8b1d6fb42e4fee58a17e608 · sha256:ff1231e860e0db1d… · /containers/cna/affected/0
{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"defaultStatus":"affected","packageName":"rest","product":"Red Hat Enterprise Linux 10","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"0:0.9.1-11.el10_2.1","versionType":"rpm"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:e2571bce33877c1f1544a76890c4dbf19e677c34d8b1d6fb42e4fee58a17e608 · sha256:ff1231e860e0db1d… · /containers/cna/affected/1
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.8,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:e2571bce33877c1f1544a76890c4dbf19e677c34d8b1d6fb42e4fee58a17e608 · sha256:ff1231e860e0db1d… · /containers/cna/metrics/1/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-338","description":"Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:e2571bce33877c1f1544a76890c4dbf19e677c34d8b1d6fb42e4fee58a17e608 · sha256:ff1231e860e0db1d… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"RHSA-2026:47085","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2026:47085"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e2571bce33877c1f1544a76890c4dbf19e677c34d8b1d6fb42e4fee58a17e608 · sha256:ff1231e860e0db1d… · /containers/cna/references/0
{"tags":["vdb-entry","x_refsource_REDHAT"],"url":"https://access.redhat.com/security/cve/CVE-2026-16615"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e2571bce33877c1f1544a76890c4dbf19e677c34d8b1d6fb42e4fee58a17e608 · sha256:ff1231e860e0db1d… · /containers/cna/references/1
{"name":"RHBZ#2504432","tags":["issue-tracking","x_refsource_REDHAT"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2504432"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e2571bce33877c1f1544a76890c4dbf19e677c34d8b1d6fb42e4fee58a17e608 · sha256:ff1231e860e0db1d… · /containers/cna/references/2
{"url":"https://gitlab.gnome.org/GNOME/librest/-/issues/25"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e2571bce33877c1f1544a76890c4dbf19e677c34d8b1d6fb42e4fee58a17e608 · sha256:ff1231e860e0db1d… · /containers/cna/references/3
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.