CVE-2026-13758

No CVSS score published

Vendor advisory ref

Source data as of:

At a glance

Severity
No CVSS score published
CVSS
No CVSS score in the NVD record
EPSS
EPSS not provided by FIRST.org for this CVE
CISA KEV
No
Published
2026-06-29 · Modified: 2026-06-29

CVSS / EPSS / KEV

EPSS EPSS not provided by FIRST.org for this CVE Source: FIRST.org
CISA KEV No Source: CISA

Source — CVSS: NVD · EPSS: FIRST.org · KEV: CISA. Data & Sources

Description

CryptX versions before 0.088_001 for Perl compare AEAD authentication tags in non-constant time in the streaming decrypt_done path. The decrypt_done($tag) form compares it against the computed tag with memNE (memcmp() != 0), which short-circuits on the first differing byte, so its run time depends on the number of matching leading bytes. This affects all five AEAD modes: GCM, CCM, ChaCha20Poly1305, EAX and OCB. The one-shot *_decrypt_verify helpers are unaffected; they verify the tag inside libtomcrypt with a constant-time comparison. The timing difference is a tag-verification oracle. An attacker who can submit many candidate tags for the same nonce, ciphertext and associated data while measuring the timing precisely enough may recover the expected tag byte by byte and forge a message that verifies.

Record details

CVE ID
CVE-2026-13758
CISA KEV
No
Weakness (CWE)
CWE-208
Affected configurations (CPE)
0
Published
2026-06-29
Modified
2026-06-29
Status
Received

References

Reference URLs as listed by NVD, grouped by a mechanical match on the link's host/pattern. Labels describe the link type only.