PatchSiren cyber security CVE debrief
CVE-2026-47373 RRWO CVE debrief
CVE-2026-47373 is a timing-attack issue in the Perl Crypt::SaltedHash module affecting versions through 0.09. The problem comes from using Perl's built-in eq comparison, which can expose timing discrepancies that may help an attacker infer information about the underlying hash. The supplied references point to a fix in Crypt::SaltedHash 0.10 and an associated security disclosure on the same day the CVE was published.
- Vendor
- RRWO
- Product
- Crypt::SaltedHash
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-20
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-20
- Advisory updated
- 2026-07-23
Who should care
Perl developers and operators using Crypt::SaltedHash through 0.09, especially in authentication, password-verification, or any code path that compares secret values or derived hashes in a remotely reachable context.
Technical summary
NVD maps this issue to CWE-208 (Observable Timing Discrepancy). According to the CVE description, Crypt::SaltedHash versions through 0.09 use Perl's built-in eq for comparison. Because eq may not take the same amount of time for all inputs, an attacker who can measure response timing may gain information about the compared hash or secret. The referenced 0.10 release notes and patch indicate a corrective change was made in the project.
Defensive priority
Medium
Recommended defensive actions
- Upgrade Crypt::SaltedHash to version 0.10 or later.
- Review application code that compares hashes, tokens, or other secrets and replace non-constant-time comparisons with a constant-time alternative where appropriate.
- Prioritize remediation for any network-facing authentication or verification flow that uses this module.
- If exposure is suspected, consider reissuing or rotating affected secrets and credentials according to your incident-response and password-management procedures.
- Verify dependency locks and deployment artifacts to ensure the fixed release is actually in use.
Evidence notes
The supplied CVE description states that versions through 0.09 are susceptible because they use Perl's built-in eq comparison. The NVD record lists CWE-208. The reference set includes a patch commit, the Crypt::SaltedHash 0.10 changes page, and an oss-security announcement, all of which support the conclusion that the issue was publicly disclosed and fixed in 0.10. The vendor/product mapping in the supplied metadata is low-confidence and marked for review, so the debrief relies on the module name and cited references rather than that mapping.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-47373 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-47373
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-47373 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47373
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/robrwo/perl-Crypt-SaltedHash/commit/c07bfc5c23185b0667233d0f2e1252d81f1f027a.patch
9b29abf9-4ab0-4765-b253-1875cd9b441e
-
Source reference
Unverified legacy reference
URL: https://metacpan.org/release/RRWO/Crypt-SaltedHash-0.10/changes
9b29abf9-4ab0-4765-b253-1875cd9b441e
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.