6.8

CVE-2026-16615

Librest: weak random number generation in pkce implementation

A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerGNOME
≫
Produkt librest
Default Statusaffected
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 10
Default Statusaffected
Version 0:0.9.1-11.el10_2.1
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 10.0 Extended Update Support
Default Statusaffected
Version 0:0.9.1-11.el10_0.1
Version < *
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.17
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 6.8 1.6 5.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.

https://access.redhat.com/security/cve/CVE-2026-16615
https://bugzilla.redhat.com/show_bug.cgi?id=2504432
https://gitlab.gnome.org/GNOME/librest/-/issues/25
https://access.redhat.com/errata/RHSA-2026:47085
https://access.redhat.com/errata/RHSA-2026:62222