CRITICAL: crypto-js — crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
Summary CryptoJS.lib.WordArray.random() in affected versions is not a cryptographically secure random number generator. Nominal requests for 128 or 256 bits of entropy produce effective search spaces of approximately 2^39 and 2^47 possibilities — small…
Source crypto-jsPublished 8d ago · Aug 7, 2026Posted on Threads

What we hold
- Package
- crypto-js
- Ecosystem
- npm
- Severity
- CRITICAL
- ID
- CVE-2026-71851
Summary CryptoJS.lib.WordArray.random() in affected versions is not a cryptographically secure random number generator. Nominal requests for 128 or 256 bits of entropy produce effective search spaces of approximately 2^39 and 2^47 possibilities — small…
Learning about advisories like this one the day they are published is a separate problem from reading them here. Dependabot alerts, the GitHub Advisory Database API, OSV.dev and npm audit, compared against live responses: how to get an alert when a dependency has a new security advisory.