๐Ÿ” CVE Alert

CVE-2026-73230

UNKNOWN 0.0

Ente: 2of3 cards v1 contain a checksum that enables offline guessing of low-entropy secrets

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Ente provides end-to-end encrypted cloud services and security tools. Prior to 2026.07.28, Ente 2of3 card format version 1 stored the secret byte length and 32-bit FNV-1a checksum in cleartext on every card, allowing someone with one card to test candidate secrets offline and recover low-entropy or predictable secrets. This issue is fixed in version 2026.07.28.

CWE CWE-200
Vendor ente
Product ente
Published Aug 11, 2026
Stay Ahead of the Next One

Get instant alerts for ente ente

Be the first to know when new unknown vulnerabilities affecting ente ente are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

ente / ente
< 2026.07.28

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/ente/ente/security/advisories/GHSA-v6x7-rrch-9q9w github.com: https://github.com/ente/ente/pull/11729 github.com: https://github.com/ente/ente/commit/6681d8370a37c2fc745d3098126ba1ee62bf06a5 github.com: https://github.com/ente/ente/commit/c3d2e400ae6fa66d5ce7df422136d28805fe1442