Description
The public SenderContext Seal() API has a race condition which allows for the same AEAD nonce to be re-used for multiple Seal() calls. This can lead to complete loss of Confidentiality and Integrity of the produced messages.
Recommendation
Update the @hpke/core package to the latest compatible version. Followings are version details:
- Affected version(s): <= 1.7.4
- Patched version(s): 1.7.5
References
Could your website be exposed too?
SmartScanner can check your website for @hpke/core reuses AEAD nonces and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Vue I18n Allows Prototype Pollution in `handleFlatJson` - @intlify/vue-i18n-core - CVE-2025-27597
- Vue I18n Allows Prototype Pollution in `handleFlatJson` - @intlify/core - CVE-2025-27597
- Vue I18n Allows Prototype Pollution in `handleFlatJson` - @intlify/core-base - CVE-2025-27597
- @farmfe/core is Missing Origin Validation in WebSocket - CVE-2025-56647


