<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T19:55:43.060883+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-44985</id>
    <title>cnvd-2021-44985</title>
    <updated>2026-10-10T19:55:43.063886+00:00</updated>
    <content>cnvd-2021-44985</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-44985"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-28070</id>
    <title>EUVD-2026-28070</title>
    <updated>2026-10-10T19:55:43.063922+00:00</updated>
    <content>EUVD-2026-28070</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-28070"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-32685</id>
    <title>fkie_cve-2021-32685</title>
    <updated>2026-10-10T19:55:43.063936+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tEnvoy contains the PGP, NaCl, and PBKDF2 in node.js and the browser (hashing, random, encryption, decryption, signatures, conversions), used by TogaTech.org. In versions prior to 7.0.3, the `verifyWithMessage` method of `tEnvoyNaClSigningKey` always returns `true` for any signature that has a SHA-512 hash matching the SHA-512 hash of the message even if the signature was invalid. This issue is patched in version 7.0.3. As a workaround: In `tenvoy.js` under the `verifyWithMessage` method definition within the `tEnvoyNaClSigningKey` class, ensure that the return statement call to `this.verify` ends in `.verified`.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-32685"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7r96-8g3x-g36m</id>
    <title>GHSA-7r96-8g3x-g36m — Improper Verification of Cryptographic Signature</title>
    <updated>2026-10-10T19:55:43.063968+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: tenvoy</p>
<p>### Impact
The `verifyWithMessage` method of `tEnvoyNaClSigningKey` always returns `true` for any signature of a SHA-512 hash matching the SHA-512 hash of the message even if the signature is invalid.</p>
<p>### Patches
Upgrade to `v7.0.3` immediately to resolve this issue. Since the vulnerability lies within the verification method, the previous signatures are still valid. We highly recommend reverifying any signatures that were previously verified with the vulnerable `verifyWithMessage` method.</p>
<p>### Workarounds
In `tenvoy.js` under the `verifyWithMessage` method definition within the `tEnvoyNaClSigningKey` class, ensure that the return statement call to `this.verify` ends in `.verified`. For example, the return statement should start with `return this.verify(signed, password).verified &amp;&amp; ` instead of `return this.verify(signed, password) &amp;&amp; `.</p>
<p>### For more information
If you have any questions or comments about this advisory:
* Open an issue in [github.com/TogaTech/tEnvoy](https://github.com/TogaTech/tEnvoy)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7r96-8g3x-g36m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-32685</id>
    <title>gsd-2021-32685</title>
    <updated>2026-10-10T19:55:43.064001+00:00</updated>
    <content>gsd-2021-32685</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-32685"/>
  </entry>
</feed>
