PT-2026-76518 · Crates.Io · Dcrypt-Algorithms

Published

2026-08-09

·

Updated

2026-08-09

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In all published versions of dcrypt-algorithms before 2.0.0, the low-level Gcm builder required an operation nonce but derived J0 from the nonce captured by the original Gcm constructor. Multiple operations could therefore silently reuse a nonce even when callers supplied distinct values, compromising confidentiality and authenticity under an affected key.
Version 2.0.0 makes Gcm key-only and passes the operation nonce through IV derivation, encryption, and decryption. It also corrects non-96-bit IV processing, rejects tags shorter than 96 bits, and enforces counter limits. Applications must upgrade, identify affected keys, rotate them, and re-encrypt affected data; updating the implementation cannot restore security after nonce reuse.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

RUSTSEC-2026-0238

Affected Products

Dcrypt-Algorithms