GHSA-r353-4845-pr5p
HIGHCVE-2026-32600XML nodes encrypted with either aes-128-gcm, aes-192-gcm, or aes-256-gcm lack validation of the authentication tag length.
- Affected
- >= 2.0.0, < 2.3.1
- Fixed in
- 2.3.1
- Weakness
- CWE-354
- Published
- 2026-03-13
- Source
- github