Get real-time updates on Telegram
CVE-2026-95105: cloak 0.1.0-pre to before *
Affected technology
cloak · 0.1.0-pre to before *
danielberkompas
cloak · 2bd17019e285b55c5c218cc842537bf9280f24c3 to before *
danielberkompas
Component: 'Elixir.Cloak.Ciphers.AES.CTR', 'Elixir.Cloak.Ciphers.Deprecated.AES.CTR'
Function: 'Elixir.Cloak.Ciphers.AES.CTR':encrypt/2, 'Elixir.Cloak.Ciphers.AES.CTR':decrypt/2, 'Elixir.Cloak.Ciphers.Deprecated.AES.CTR':decrypt/2
File: lib/cloak/ciphers/aes_ctr.ex, lib/cloak/ciphers/deprecated/aes_ctr.ex
Attack conditions (Source advisory, CVSS 4.0): Network (remote) · No privileges required · No user interaction required
What an attacker can do
An attacker with write access to stored ciphertext to make it decrypt can a chosen value via bit flipping. Source advisory’s CVSS 4.0 assessment (base score 8.2/10) rates confidentiality and availability impact as none; integrity impact as high.
- CWE
- CWE-649
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-06 10:41:36.128766+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-06 17:55:17.257073+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-95105.html