CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-95105: cloak 0.1.0-pre to before *

Affected technology

cloak · 0.1.0-pre to before *
danielberkompas

cloak · 2bd17019e285b55c5c218cc842537bf9280f24c3 to before *
danielberkompas

Component: 'Elixir.Cloak.Ciphers.AES.CTR', 'Elixir.Cloak.Ciphers.Deprecated.AES.CTR'
Function: 'Elixir.Cloak.Ciphers.AES.CTR':encrypt/2, 'Elixir.Cloak.Ciphers.AES.CTR':decrypt/2, 'Elixir.Cloak.Ciphers.Deprecated.AES.CTR':decrypt/2
File: lib/cloak/ciphers/aes_ctr.ex, lib/cloak/ciphers/deprecated/aes_ctr.ex

Attack conditions (Source advisory, CVSS 4.0): Network (remote) · No privileges required · No user interaction required

What an attacker can do

An attacker with write access to stored ciphertext to make it decrypt can a chosen value via bit flipping. Source advisory’s CVSS 4.0 assessment (base score 8.2/10) rates confidentiality and availability impact as none; integrity impact as high.

Published

CWE
CWE-649
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-95105.html