Google

Tink Java

2 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 21.07.2026 16:42:12
  • Zuletzt bearbeitet 22.09.2026 13:09:49

When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time comparison. This potentially allows an attacker to use timinig information as a side channel in order to get information how many bytes ...

  • EPSS 0.46%
  • Veröffentlicht 19.10.2020 13:15:13
  • Zuletzt bearbeitet 05.06.2025 14:50:15

A mis-handling of invalid unicode characters in the Java implementation of Tink versions prior to 1.5 allows an attacker to change the ID part of a ciphertext, which result in the creation of a second ciphertext that can decrypt to the same plaintext...