Summary
| Parameter | Value |
|---|---|
| CVE ID | CVE-2025-15638 |
| Alert Source | GitHub Advisory - Critical Vulnerability |
| CVE Publication Year | 2025 |
| Date Published | 2026-04-21 |
| Vendor | Perl |
| Product | Net::Dropbear |
| CVSS Score | 10.0 (critical) |
| EPSS Score | No data |
| CISA KEV | No |
| Ransomware | Not confirmed |
Vulnerability Description
Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt.
Net::Dropbear versions before 0.14 includes versions of Dropbear 2019.78 or earlier. These include versions of libtomcrypt v1.18.1 or earlier, which is affected by CVE-2016-6129 and CVE-2018-12437.
Required Actions
Apply vendor patches or mitigations as soon as available.
Who Is Affected?
This vulnerability affects the Net::Dropbear module for Perl. Check whether your organization uses this software and requires updating to version 0.14 or later.
Sources
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
