---
id: CVE-2026-57082
title: >-
  Net::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie-Hellman
  private key with a non-cryptographic PRNG.


  The MSE (Message Stream Encryption) handshake derives its 160-bit
  Diffie-Hellman private key from Perl's rand(), a…
summary: >-
  Net::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie-Hellman
  private key with a non-cryptographic PRNG.


  The MSE (Message Stream Encryption) handshake derives its 160-bit
  Diffie-Hellman private key from Perl's rand(), a…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-330
  - CWE-338
published: '2026-06-30'
updated: '2026-07-20'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-57082'
references:
  - url: >-
      https://github.com/sanko/Net-BitTorrent.pm/security/advisories/GHSA-g444-x2c5-94hc
    label: 9b29abf9-4ab0-4765-b253-1875cd9b441e
  - url: 'https://metacpan.org/release/SANKO/Net-BitTorrent-v2.1.0/changes'
    label: 9b29abf9-4ab0-4765-b253-1875cd9b441e
tags:
  - nvd
epss: 0.00234
epssPercentile: 0.12828
ingestedAt: '2026-07-20T07:36:55.701Z'
---

## Overview

Net::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG.

The MSE (Message Stream Encryption) handshake derives its 160-bit Diffie-Hellman private key from Perl's rand(), a non-cryptographic drand48-class generator seeded once per process, in KeyExchange.pm. The shared secret and the RC4 keys derived from it (the SHA-1 of "keyA" or "keyB", the shared secret, and the infohash) therefore depend entirely on a predictable PRNG. The same handshake sends, in cleartext, random padding drawn from the same rand() sequence in _random_pad, immediately after the public key and the private-key draw.

A passive observer of the handshake recovers the PRNG state from the cleartext padding, reconstructs the private key, computes the shared secret from the peer's public key on the wire, derives the RC4 keys, and decrypts the connection, defeating the passive-observation obfuscation MSE provides.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
