AES-GCM encryption/decryption with extremely large cumulative single message sizes (>64 GiB) were not properly rejected by the streaming APIs, allowing counter wrap, keystream reuse, and consequent plaintext recovery.
{
"license": "CC-BY-4.0",
"sources": [
{
"modified": "2026-06-26T16:50:50Z",
"url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-55967",
"imported": "2026-07-17T22:33:53.458Z",
"database_specific": {
"status": "Analyzed"
},
"html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55967",
"id": "CVE-2026-55967",
"published": "2026-06-25T18:16:41.330Z"
},
{
"modified": "2026-06-26T18:33:49Z",
"url": "https://api.github.com/advisories/GHSA-q4q5-jx42-4xp9",
"imported": "2026-07-17T22:33:53.633Z",
"html_url": "https://github.com/advisories/GHSA-q4q5-jx42-4xp9",
"published": "2026-06-25T18:30:41Z",
"id": "GHSA-q4q5-jx42-4xp9"
},
{
"modified": "2026-06-25T17:57:09Z",
"url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-39493",
"imported": "2026-07-17T22:34:03.538Z",
"html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-39493",
"id": "EUVD-2026-39493",
"published": "2026-06-25T16:53:14Z"
}
]
}