CVE-2026-71851 – crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
CVE ID :CVE-2026-71851 Published : Aug. 7, 2026, 7:18 p.m. | 30 minutes ago Description :crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom…
