PT-2025-38638 · Starch · Starch

CVE-2025-40925

·

Published

2025-09-20

·

Updated

2025-09-21

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Starch versions 0.14 and earlier
Description Starch generates session IDs insecurely. The default session ID generator returns a SHA-1 hash seeded with a counter, the epoch time, the built-in rand function, the PID, and internal Perl reference addresses. The PID will come from a small set of numbers, and the epoch time may be guessed. The rand function is unsuitable for cryptographic usage. Predictable session IDs could allow an attacker to gain access to systems.
Recommendations Update Starch to a version later than 0.14.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-40925

Affected Products

Starch