Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-95105— Cloak AES-CTR cipher lacks ciphertext authentication, allowing chosen-plaintext forgery by bit flipping

Quick assessment

Affected
danielberkompas cloak
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

漏洞描述翻译如下: 未对安全相关输入进行完整性检查的漏洞(依赖混淆或加密) 在 库中,攻击者只要拥有对密文的写权限,就可以通过位翻转(bit flipping)技术,使得密文解密后变为攻击者指定的值。 使用 AES-256-CTR 模式进行加密,并将密钥标签(key tag)、初始化向量(IV)和密文一并存储,但未使用消息认证码(MAC)。 函数在返回明文之前,仅校验密钥标签和最小长度。 在解密旧格式数据时也采用相同的验证方式。 由于 CTR 是一种流密码模式,对密文中某位置进行异或操作,会在相同偏移位置对解密后的

CVSS 8.2 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-95105

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cloak AES-CTR cipher lacks ciphertext authentication, allowing chosen-plaintext forgery by bit flipping
Source: CVE Program / CVE List V5
Vulnerability Description
Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking vulnerability in danielberkompas cloak allows an attacker with write access to stored ciphertext to make it decrypt to a chosen value via bit flipping. Cloak.Ciphers.AES.CTR encrypts with AES-256 in CTR mode and stores the key tag, the IV and the ciphertext with no MAC. decrypt/2 checks only the key tag and the minimum length before it returns the plaintext, and Cloak.Ciphers.Deprecated.AES.CTR decrypts the legacy format the same way. CTR is a stream cipher, so a value XORed into the stored ciphertext is XORed into the plaintext at the same offset. An attacker who can write to the encrypted store (for example through SQL injection or a compromised replica) and who knows or can guess a stored plaintext can replace it with any value of the same length. The application receives that value with no error. This issue affects cloak: from 0.1.0-pre onward.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
依赖于未经完整性检查的安全相关输入的混淆或加密
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
danielberkompas cloak 0.1.0-pre ~ * cpe:2.3:a:danielberkompas:cloak:*:*:*:*:*:*:*:*
danielberkompas cloak 2bd17019e285b55c5c218cc842537bf9280f24c3 ~ * cpe:2.3:a:danielberkompas:cloak:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-95105

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-95105

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-95105 (1)

Other References for CVE-2026-95105 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-95105

No comments yet


Leave a comment