THREAT OPS › Threat News › [GHSA] GHSA-rg76-677x-56q9 (critical) — crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
[GHSA] GHSA-rg76-677x-56q9 (critical) — crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
GHSA-rg76-677x-56q9 Severity: critical CVE: CVE-2026-71851
crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
### Summary
`CryptoJS.lib.WordArray.random()` in affected versions is not a cryptographically secure random number generator. Nominal requests for 128 or 256 bits of entropy produce effective search spaces of approximately 2^39 an
MITRE ATT&CK techniques
- Private KeysT1552.004
Indicators of compromise
- ff1f0032ff58aedfcc44eb6aa7b2c78207a98009sha1
- CVE-2026-71851cve
- https://www.coinspect.com/blog/ill-bloom-investigation/url
- https://illbloom.org/url
Original source: https://github.com/advisories/GHSA-rg76-677x-56q9