πŸ” CVE Alert

CVE-2026-95105

UNKNOWN 0.0

Cloak AES-CTR cipher lacks ciphertext authentication, allowing chosen-plaintext forgery by bit flipping

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking vulnerability in danielberkompas cloak allows an attacker with write access to stored ciphertext to make it decrypt to a chosen value via bit flipping. Cloak.Ciphers.AES.CTR encrypts with AES-256 in CTR mode and stores the key tag, the IV and the ciphertext with no MAC. decrypt/2 checks only the key tag and the minimum length before it returns the plaintext, and Cloak.Ciphers.Deprecated.AES.CTR decrypts the legacy format the same way. CTR is a stream cipher, so a value XORed into the stored ciphertext is XORed into the plaintext at the same offset. An attacker who can write to the encrypted store (for example through SQL injection or a compromised replica) and who knows or can guess a stored plaintext can replace it with any value of the same length. The application receives that value with no error. This issue affects cloak: from 0.1.0-pre onward.

CWE CWE-649
Vendor danielberkompas
Product cloak
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for danielberkompas cloak

Be the first to know when new unknown vulnerabilities affecting danielberkompas cloak are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

Affected Versions

danielberkompas / cloak
0.1.0-pre < *
danielberkompas / cloak
2bd17019e285b55c5c218cc842537bf9280f24c3 < *

References

NVD β†— CVE.org β†— EPSS Data β†—
cna.erlef.org: https://cna.erlef.org/cves/CVE-2026-95105.html osv.dev: https://osv.dev/vulnerability/EEF-CVE-2026-95105 github.com: https://github.com/danielberkompas/cloak/commit/2bd17019e285b55c5c218cc842537bf9280f24c3

Credits

Peter Ullrich πŸ” Peter Ullrich Jonatan MΓ€nnchen / EEF