<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 19:55:29 +0000</lastBuildDate>
    <item>
      <title>cnvd-2021-44985</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-44985</link>
      <description>cnvd-2021-44985</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-44985</guid>
    </item>
    <item>
      <title>EUVD-2026-28070</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-28070</link>
      <description>EUVD-2026-28070</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-28070</guid>
    </item>
    <item>
      <title>fkie_cve-2021-32685</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-32685</link>
      <description>&lt;p&gt;tEnvoy contains the PGP, NaCl, and PBKDF2 in node.js and the browser (hashing, random, encryption, decryption, signatures, conversions), used by TogaTech.org. In versions prior to 7.0.3, the `verifyWithMessage` method of `tEnvoyNaClSigningKey` always returns `true` for any signature that has a SHA-512 hash matching the SHA-512 hash of the message even if the signature was invalid. This issue is patched in version 7.0.3. As a workaround: In `tenvoy.js` under the `verifyWithMessage` method definition within the `tEnvoyNaClSigningKey` class, ensure that the return statement call to `this.verify` ends in `.verified`.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tEnvoy contains the PGP, NaCl, and PBKDF2 in node.js and the browser (hashing, random, encryption, decryption, signatures, conversions), used by TogaTech.org. In versions prior to 7.0.3, the `verifyWithMessage` method of `tEnvoyNaClSigningKey` always returns `true` for any signature that has a SHA-512 hash matching the SHA-512 hash of the message even if the signature was invalid. This issue is patched in version 7.0.3. As a workaround: In `tenvoy.js` under the `verifyWithMessage` method definition within the `tEnvoyNaClSigningKey` class, ensure that the return statement call to `this.verify` ends in `.verified`.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-32685</guid>
    </item>
    <item>
      <title>GHSA-7r96-8g3x-g36m — Improper Verification of Cryptographic Signature</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7r96-8g3x-g36m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: tenvoy&lt;/p&gt;
&lt;p&gt;### Impact
The `verifyWithMessage` method of `tEnvoyNaClSigningKey` always returns `true` for any signature of a SHA-512 hash matching the SHA-512 hash of the message even if the signature is invalid.&lt;/p&gt;
&lt;p&gt;### Patches
Upgrade to `v7.0.3` immediately to resolve this issue. Since the vulnerability lies within the verification method, the previous signatures are still valid. We highly recommend reverifying any signatures that were previously verified with the vulnerable `verifyWithMessage` method.&lt;/p&gt;
&lt;p&gt;### Workarounds
In `tenvoy.js` under the `verifyWithMessage` method definition within the `tEnvoyNaClSigningKey` class, ensure that the return statement call to `this.verify` ends in `.verified`. For example, the return statement should start with `return this.verify(signed, password).verified &amp;amp;&amp;amp; ` instead of `return this.verify(signed, password) &amp;amp;&amp;amp; `.&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Open an issue in [github.com/TogaTech/tEnvoy](https://github.com/TogaTech/tEnvoy)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: tenvoy&lt;/p&gt;
&lt;p&gt;### Impact
The `verifyWithMessage` method of `tEnvoyNaClSigningKey` always returns `true` for any signature of a SHA-512 hash matching the SHA-512 hash of the message even if the signature is invalid.&lt;/p&gt;
&lt;p&gt;### Patches
Upgrade to `v7.0.3` immediately to resolve this issue. Since the vulnerability lies within the verification method, the previous signatures are still valid. We highly recommend reverifying any signatures that were previously verified with the vulnerable `verifyWithMessage` method.&lt;/p&gt;
&lt;p&gt;### Workarounds
In `tenvoy.js` under the `verifyWithMessage` method definition within the `tEnvoyNaClSigningKey` class, ensure that the return statement call to `this.verify` ends in `.verified`. For example, the return statement should start with `return this.verify(signed, password).verified &amp;amp;&amp;amp; ` instead of `return this.verify(signed, password) &amp;amp;&amp;amp; `.&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Open an issue in [github.com/TogaTech/tEnvoy](https://github.com/TogaTech/tEnvoy)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7r96-8g3x-g36m</guid>
    </item>
    <item>
      <title>gsd-2021-32685</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-32685</link>
      <description>gsd-2021-32685</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-32685</guid>
    </item>
  </channel>
</rss>
