PT-2026-7944 · Unknown · Www::Oauth

Robert Rothenberg

·

Published

2025-01-01

·

Updated

2026-02-18

·

CVE-2025-40905

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions WWW::OAuth versions 1.000 and earlier
Description The software utilizes the rand() function as the default source of entropy for cryptographic functions, which is not cryptographically secure. This can potentially compromise the security of cryptographic operations.
Recommendations Versions prior to 1.000 should be updated. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2025-40905

Affected Products

Www::Oauth