CVE-2025-64767

hpke-js is a Hybrid Public Key Encryption (HPKE) module built on top of Web Cryptography API. Prior to version 1.7.5, the public SenderContext Seal() API has a race condition which allows for the same AEAD nonce to be re-used for multiple Seal() calls. This can lead to complete loss of Confidentiality and Integrity of the produced messages. This issue has been patched in version 1.7.5.
Configurations

No configuration.

History

21 Nov 2025, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-21 19:16

Updated : 2025-11-25 22:16


NVD link : CVE-2025-64767

Mitre link : CVE-2025-64767

CVE.ORG link : CVE-2025-64767


JSON object : View

Products Affected

No product.

CWE
CWE-323

Reusing a Nonce, Key Pair in Encryption