CVE Explorer
CVE-2026-5083
Ado::Sessions versions through 0.935 for Perl generates insecure session ids.
The session id is generated from a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage.
Predicable session ids could allow an attacker to gain access to systems.
Note that Ado is no longer maintain
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-340","description":"CWE-340 Generation of Predictable Numbers or Identifiers","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2d66974b8204027811e2a63409a46081bb0905cdd413ed9aed88a9124b7d0226 · sha256:f26fd97ba7c838e8… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-338","description":"CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2d66974b8204027811e2a63409a46081bb0905cdd413ed9aed88a9124b7d0226 · sha256:f26fd97ba7c838e8… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"collectionURL":"https://cpan.org/modules","defaultStatus":"unaffected","packageName":"Ado","product":"Ado::Sessions","programFiles":["lib/Ado/Session.pm"],"programRoutines":[{"name":"Ado::Sessions::generate_id"}],"repo":"https://github.com/kberov/Ado","vendor":"BEROV","versions":[{"lessThanOrEqual":"0.935","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:2d66974b8204027811e2a63409a46081bb0905cdd413ed9aed88a9124b7d0226 · sha256:f26fd97ba7c838e8… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:2d66974b8204027811e2a63409a46081bb0905cdd413ed9aed88a9124b7d0226 · sha256:f26fd97ba7c838e8… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-340","description":"CWE-340 Generation of Predictable Numbers or Identifiers","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2d66974b8204027811e2a63409a46081bb0905cdd413ed9aed88a9124b7d0226 · sha256:f26fd97ba7c838e8… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-338","description":"CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2d66974b8204027811e2a63409a46081bb0905cdd413ed9aed88a9124b7d0226 · sha256:f26fd97ba7c838e8… · /containers/cna/problemTypes/1/descriptions/0
Source references
4 source assertions{"url":"http://www.openwall.com/lists/oss-security/2026/04/08/7"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2d66974b8204027811e2a63409a46081bb0905cdd413ed9aed88a9124b7d0226 · sha256:f26fd97ba7c838e8… · /containers/adp/1/references/0
{"url":"https://backpan.perl.org/authors/id/B/BE/BEROV/Ado-0.935.tar.gz"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2d66974b8204027811e2a63409a46081bb0905cdd413ed9aed88a9124b7d0226 · sha256:f26fd97ba7c838e8… · /containers/cna/references/1
{"tags":["issue-tracking"],"url":"https://github.com/kberov/Ado/issues/112"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2d66974b8204027811e2a63409a46081bb0905cdd413ed9aed88a9124b7d0226 · sha256:f26fd97ba7c838e8… · /containers/cna/references/0
{"tags":["technical-description"],"url":"https://security.metacpan.org/docs/guides/random-data-for-security.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2d66974b8204027811e2a63409a46081bb0905cdd413ed9aed88a9124b7d0226 · sha256:f26fd97ba7c838e8… · /containers/cna/references/2
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.