{"id":"CVE-2025-22376","details":"In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, the default nonce is a 32-bit integer generated from the built-in rand() function, which is not cryptographically strong.","modified":"2026-08-15T11:45:19.839258280Z","published":"2025-01-03T00:00:00Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/22xxx/CVE-2025-22376.json","cna_assigner":"mitre","cwe_ids":["CWE-338"]},"references":[{"type":"WEB","url":"https://datatracker.ietf.org/doc/html/rfc5849#section-3.3"},{"type":"WEB","url":"https://datatracker.ietf.org/doc/html/rfc5849#section-4.10"},{"type":"WEB","url":"https://metacpan.org/release/KGRENNAN/Net-OAuth-0.28/source/lib/Net/OAuth/Client.pm#L260"},{"type":"WEB","url":"https://metacpan.org/release/RRWO/Net-OAuth-0.29/changes"},{"type":"WEB","url":"https://metacpan.org/release/RRWO/Net-OAuth-0.29/diff/KGRENNAN/Net-OAuth-0.28#lib/Net/OAuth/Client.pm"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/22xxx/CVE-2025-22376.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-22376"},{"type":"FIX","url":"https://github.com/keeth/Net-OAuth/commit/2aa25e04aadab247ae4063363fcee177161e1f42"},{"type":"ARTICLE","url":"https://www.vulnarium.com/blogpost-2025-01-05"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/vurtdev/Net-OAuth","events":[{"introduced":"0"},{"fixed":"2aa25e04aadab247ae4063363fcee177161e1f42"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.29"}],"source":["DESCRIPTION","REFERENCES"]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-22376.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}