CVE-2026-47372
Crypt::SaltedHash could allow external attacker to compromise user passwords.
Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.
Crypt::SaltedHash contains a flaw that allows an external attacker to predict the security codes protecting stored passwords. By cracking these passwords, attackers can gain unauthorized account access, potentially exposing sensitive customer data or compromising administrative systems.