PT-2025-38638 · Starch · Starch

Published

2025-09-20

·

Updated

2025-09-21

·

CVE-2025-40925

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Starch versions 0.14 and earlier
Description Starch generates session IDs insecurely. The default session ID generator returns a SHA-1 hash seeded with a counter, the epoch time, the built-in rand function, the PID, and internal Perl reference addresses. The PID will come from a small set of numbers, and the epoch time may be guessed. The rand function is unsuitable for cryptographic usage. Predictable session IDs could allow an attacker to gain access to systems.
Recommendations Update Starch to a version later than 0.14.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-40925

Affected Products

Starch