GHSA-73g8-5h73-26h4
CRITICALCVE-2025-64767The public SenderContext Seal() API has a race condition which allows for the same AEAD nonce to be re-used for multiple Seal() calls. This can lead to complete loss of Confidentiality and Integrity of the produced messages.
- Affected
- <= 1.7.4
- Fixed in
- 1.7.5
- Weakness
- CWE-323
- Published
- 2025-11-20
- Source
- github