A vulnerability was found in DRSTEVE Crypt::Password up to 0.28. It has been rated as problematic. Affected is an unknown function of the file lib/Crypt/Password.pm of the component rand. The manipulation leads to insufficiently random values.
This vulnerability is referenced as CVE-2026-16235. Remote exploitation of the attack is possible. No exploit is available.