<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 20:56:25 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-292975</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-292975</link>
      <description>EUVD-2026-292975</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-292975</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41244</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41244</link>
      <description>&lt;p&gt;Mojic is a CLI tool to transform readable C code into an unrecognizable chaotic stream of emojis. Prior to 2.1.4, the CipherEngine uses a standard equality operator (!==) to verify the HMAC-SHA256 integrity seal during the decryption phase. This creates an Observable Timing Discrepancy (CWE-208), allowing a potential attacker to bypass the file integrity check via a timing attack. This vulnerability is fixed in 2.1.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Mojic is a CLI tool to transform readable C code into an unrecognizable chaotic stream of emojis. Prior to 2.1.4, the CipherEngine uses a standard equality operator (!==) to verify the HMAC-SHA256 integrity seal during the decryption phase. This creates an Observable Timing Discrepancy (CWE-208), allowing a potential attacker to bypass the file integrity check via a timing attack. This vulnerability is fixed in 2.1.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41244</guid>
    </item>
    <item>
      <title>GHSA-wqq3-wfmp-v85g — Mojic: Observable Timing Discrepancy in HMAC Verification</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wqq3-wfmp-v85g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: mojic&lt;/p&gt;
&lt;p&gt;### Summary
The `CipherEngine` in Mojic v2.1.3 uses a standard equality operator (`!==`) to verify the HMAC-SHA256 integrity seal during the decryption phase. This creates an Observable Timing Discrepancy (CWE-208), allowing a potential attacker to bypass the file integrity check via a timing attack.&lt;/p&gt;
&lt;p&gt;### Details
In `lib/CipherEngine.js`, the footer check validates the HMAC signature using a standard string comparison:
`if (footerHex !== calcDigest) { ... }`&lt;/p&gt;
&lt;p&gt;Standard string comparisons in JavaScript short-circuit; they return `false` the moment a character mismatch occurs. Because the time taken to evaluate the comparison is proportional to the number of matching leading bytes, an attacker can measure the exact microseconds it takes for the engine to throw the `FILE_TAMPERED` error. By repeatedly altering the signature byte-by-byte and analyzing these minute timing differences, a malicious actor can theoretically forge a valid HMAC signature without possessing the decryption password.&lt;/p&gt;
&lt;p&gt;### PoC
The vulnerable implementation is located in `lib/CipherEngine.js`, within the `getDecryptStream()` flush method (approximately line 265):&lt;/p&gt;
&lt;p&gt;```javascript
// Vulnerable Code
if (footerHex !== calcDigest) {
    this.emit(&amp;#39;error&amp;#39;, new Error(&amp;#34;FILE_TAMPERED&amp;#34;));
    return;
}
```&lt;/p&gt;
&lt;p&gt;### Recommended Remediation:
Replace the standard equality operator with Node.js&amp;#39;s built-in constant-time comparison utility, crypto.timingSafeEqual().&lt;/p&gt;
&lt;p&gt;```JavaScript
// Remediated Code
const footerBuffer = Buffer.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: mojic&lt;/p&gt;
&lt;p&gt;### Summary
The `CipherEngine` in Mojic v2.1.3 uses a standard equality operator (`!==`) to verify the HMAC-SHA256 integrity seal during the decryption phase. This creates an Observable Timing Discrepancy (CWE-208), allowing a potential attacker to bypass the file integrity check via a timing attack.&lt;/p&gt;
&lt;p&gt;### Details
In `lib/CipherEngine.js`, the footer check validates the HMAC signature using a standard string comparison:
`if (footerHex !== calcDigest) { ... }`&lt;/p&gt;
&lt;p&gt;Standard string comparisons in JavaScript short-circuit; they return `false` the moment a character mismatch occurs. Because the time taken to evaluate the comparison is proportional to the number of matching leading bytes, an attacker can measure the exact microseconds it takes for the engine to throw the `FILE_TAMPERED` error. By repeatedly altering the signature byte-by-byte and analyzing these minute timing differences, a malicious actor can theoretically forge a valid HMAC signature without possessing the decryption password.&lt;/p&gt;
&lt;p&gt;### PoC
The vulnerable implementation is located in `lib/CipherEngine.js`, within the `getDecryptStream()` flush method (approximately line 265):&lt;/p&gt;
&lt;p&gt;```javascript
// Vulnerable Code
if (footerHex !== calcDigest) {
    this.emit(&amp;#39;error&amp;#39;, new Error(&amp;#34;FILE_TAMPERED&amp;#34;));
    return;
}
```&lt;/p&gt;
&lt;p&gt;### Recommended Remediation:
Replace the standard equality operator with Node.js&amp;#39;s built-in constant-time comparison utility, crypto.timingSafeEqual().&lt;/p&gt;
&lt;p&gt;```JavaScript
// Remediated Code
const footerBuffer = Buffer.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wqq3-wfmp-v85g</guid>
    </item>
  </channel>
</rss>
