Vulnerability DatabaseGHSA-3fmq-x9q6-wm39

GHSA-3fmq-x9q6-wm39
PHP vulnerability analysis and mitigation

Overview

The random_compat library versions prior to 2.0 contain a security vulnerability related to insecure usage of Cryptographically Secure Pseudo-Random Number Generators (CSPRNG). The vulnerability was discovered on March 16, 2016, affecting the paragonie/random_compat Composer package. The issue stems from the library's use of openssl_random_pseudo_bytes(), which could potentially compromise the security of generated random numbers (GitHub Advisory).

Technical details

The vulnerability is classified with CWE-331 and has been assigned a low severity rating. The core issue involves the use of OpenSSL's CSPRNG implementation, which was found to use MD5 as its basis, potentially resulting in insufficient entropy. Additionally, the OpenSSL implementation was discovered to be not fork-safe and would sometimes provide misleading information about its security status (Random Issue).

Impact

The vulnerability could potentially compromise the security of random number generation in applications using the affected versions of random_compat. This could have implications for any security-critical operations that rely on these random numbers, such as cryptographic operations or token generation (GitHub Advisory).

Mitigation and workarounds

Users are advised to upgrade to random_compat version 2.0 or later, which removes the dependency on OpenSSL's CSPRNG implementation. The updated version implements more secure alternatives for random number generation. For PHP 7 users, the built-in random_bytes() function, which is based on libsodium's implementation, is recommended as a secure alternative (Random Issue).

Community reactions

The vulnerability discovery led to significant discussion within the PHP security community. The project maintainers decided to address the issue by completely removing OpenSSL support in favor of more secure alternatives. The decision was supported by various community members and security experts, who agreed that the status quo was unacceptable (Random Issue).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-67355HIGH8.2
  • PHP logoPHP
  • drupal-11.3
NoYesAug 01, 2026
CVE-2026-67354HIGH8.2
  • PHP logoPHP
  • guzzlehttp/guzzle
NoYesAug 01, 2026
CVE-2026-69246HIGH7.2
  • PHP logoPHP
  • guzzle
NoYesAug 03, 2026
CVE-2026-67353MEDIUM6.9
  • PHP logoPHP
  • drupal-11.3
NoYesAug 01, 2026
CVE-2026-69245MEDIUM6.5
  • PHP logoPHP
  • nextcloud-server-31
NoYesAug 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management