THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-rg76-677x-56q9 (critical) — crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain

[GHSA] GHSA-rg76-677x-56q9 (critical) — crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain

highgithub_advisoriesPublished 2026-08-07

GHSA-rg76-677x-56q9 Severity: critical CVE: CVE-2026-71851

crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain

### Summary

`CryptoJS.lib.WordArray.random()` in affected versions is not a cryptographically secure random number generator. Nominal requests for 128 or 256 bits of entropy produce effective search spaces of approximately 2^39 an

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-rg76-677x-56q9