Tag: Security
-
AEAD without the tag: a ChaCha20-Poly1305 story
The authentication tag was computed, then dropped. What remained looked like an AEAD and authenticated nothing. GHSA-6vvh-pxr4-25r7.
-
One number, one denial of service: PBES2 and p2c
A password-based algorithm lets the token say how many iterations to run. Nothing said it had to be a reasonable number. GHSA-3prj-6hqw-cm82.
-
A padding oracle in RSA1_5, and what constant-time rejection means
Distinguishing a bad padding from a good one is enough to decrypt without the key. Bleichenbacher, twenty-seven years later, and the fix that looks like doing nothing.
-
Algorithm confusion: when alg comes from the wrong header
A single array spread, and the algorithm a verifier trusts came from a header nobody signed. GHSA-jc38-x7x8-2xc8, found and fixed in JWT-Framework.