THREAT OPS › Threat News › [NVD] CVE-2026-71851 (CRITICAL 9.0) — crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded from Math.random(), instead of a cryptograp
[NVD] CVE-2026-71851 (CRITICAL 9.0) — crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded from Math.random(), instead of a cryptograp
CVE-2026-71851 CVSS: 9.0 CRITICAL Published: 2026-08-07T19:18:54.390
crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded from Math.random(), instead of a cryptographically secure source. This generator was introduc
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-71851cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-71851