<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T12:11:11.833419+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-268821</id>
    <title>EUVD-2026-268821</title>
    <updated>2026-10-02T12:11:11.881101+00:00</updated>
    <content>EUVD-2026-268821</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-268821"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-69287</id>
    <title>fkie_cve-2025-69287</title>
    <updated>2026-10-02T12:11:11.881137+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The BSV Blockchain SDK is a unified TypeScript SDK for developing scalable apps on the BSV Blockchain. Prior to version 2.0.0, a cryptographic vulnerability in the TypeScript SDK's BRC-104 authentication implementation caused incorrect signature data preparation, resulting in signature incompatibility between SDK implementations and potential authentication bypass scenarios. The vulnerability was located in the `Peer.ts` file of the TypeScript SDK, specifically in the `processInitialRequest` and `processInitialResponse` methods where signature data is prepared for BRC-104 mutual authentication. The TypeScript SDK incorrectly prepared signature data by concatenating base64-encoded nonce strings (`message.initialNonce + sessionNonce`) then decoding the concatenated base64 string (`base64ToBytes(concatenatedString)`). This produced ~32-34 bytes of signature data instead of the correct 64 bytes. BRC-104 authentication relies on cryptographic signatures to establish mutual trust between peers. When signature data preparation is incorrect, signatures generated by the TypeScript SDK don't match those expected by Go/Python SDKs; cross-implementation authentication fails; and an attacker could potentially exploit this to bypass authentication checks. The fix in version 2.0.0 ensures all SDKs now produce identical cryptographic signatures, restoring proper mutual authentication across implementations.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-69287"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vjpq-xx5g-qvmm</id>
    <title>GHSA-vjpq-xx5g-qvmm — BSV Blockchain SDK has an Authentication Signature Data Preparation Vulnerability</title>
    <updated>2026-10-02T12:11:11.881179+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @bsv/sdk</p>
<p># BRC-104 Authentication Signature Data Preparation Vulnerability</p>
<p>### Summary
A critical cryptographic vulnerability in the TypeScript SDK's BRC-104 authentication implementation caused incorrect signature data preparation, resulting in signature incompatibility [between SDK implementations](https://github.com/F1r3Hydr4nt/brc104-cross-language-tests) and potential authentication bypass scenarios.</p>
<p>### Details
The vulnerability was located in the `Peer.ts` file of the TypeScript SDK, specifically in the `processInitialRequest` and `processInitialResponse` methods where signature data is prepared for BRC-104 mutual authentication.</p>
<p>**Vulnerable Code Locations:**
- `ts-sdk/src/auth/Peer.ts` lines 527-531 (signing)
- `ts-sdk/src/auth/Peer.ts` lines 584-590 (verification)</p>
<p>**Root Cause:**
The TypeScript SDK incorrectly prepared signature data by:
1. Concatenating base64-encoded nonce strings: `message.initialNonce + sessionNonce`
2. Then decoding the concatenated base64 string: `base64ToBytes(concatenatedString)`</p>
<p>This produced ~32-34 bytes of signature data instead of the correct 64 bytes.</p>
<p>**Buggy Implementation (Before Fix):**
```typescript
// CRITICAL BUG: Concatenating base64 strings before decoding
data: Peer.base64ToBytes(message.initialNonce + sessionNonce)
```</p>
<p>**Correct Implementation (After Fix):**
The fix properly decodes each base64 nonce individually, then concatenates the byte arrays:
```typescript
data: [
  ...Peer.base64ToBytes(message.initialNonce),
  ...Peer.b…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vjpq-xx5g-qvmm"/>
  </entry>
</feed>
