CVE-2025-64767

hpke-js is a Hybrid Public Key Encryption (HPKE) module built on top of Web Cryptography API. Prior to version 1.7.5, the public SenderContext Seal() API has a race condition which allows for the same AEAD nonce to be re-used for multiple Seal() calls. This can lead to complete loss of Confidentiality and Integrity of the produced messages. This issue has been patched in version 1.7.5.
Configurations

No configuration.

History

No history.

Information

Published : 2025-11-21 19:16

Updated : 2025-11-25 22:16


NVD link : CVE-2025-64767

Mitre link : CVE-2025-64767

CVE.ORG link : CVE-2025-64767


JSON object : View

Products Affected

No product.

CWE
CWE-323

Reusing a Nonce, Key Pair in Encryption