Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter… (CVE-2026-71225)

0
Medium
Published: 08/05/2026 (08/05/2026, 15:32:17 UTC)
Source: GCVE Database

Description

A vulnerability in libkcapi causes improper reuse of the Initialization Vector (IV) during one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes like CTR and CBC. This IV reuse weakens data confidentiality by exposing relationships in encrypted plaintext and may affect data integrity due to incorrect cryptographic processing. The flaw can be exploited remotely by crafting large inputs processed by applications using libkcapi. Mitigation involves avoiding one-shot APIs for inputs exceeding 64 KiB and using the streaming interface instead.

CVSS v3.1

Score 6.5medium

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/05/2026, 22:03:52 UTC

Technical Analysis

CVE-2026-71225 is a cryptographic vulnerability in libkcapi where one-shot symmetric cipher operations on inputs larger than 64 KiB in stateful modes (e.g., Counter (CTR) or Cipher Block Chaining (CBC)) improperly reuse the Initialization Vector (IV) for each internal data chunk. This reuse of IV compromises the confidentiality of encrypted data by revealing relationships between plaintext chunks and may also impact data integrity due to incorrect cryptographic processing. The vulnerability can be triggered remotely by supplying specially crafted large inputs to applications utilizing libkcapi. The vendor advisory recommends avoiding one-shot symmetric cipher APIs for large inputs and instead using the streaming interface or ensuring input sizes remain below the chunking threshold to maintain IV consistency.

Potential Impact

The vulnerability leads to a significant weakening of data confidentiality because repeated IV use in stateful cipher modes can expose relationships in encrypted plaintext. It may also affect data integrity by causing incorrect cryptographic processing. The CVSS v3.1 score is 6.5 (medium severity) with high confidentiality impact, low integrity impact, and no availability impact. There are no known exploits in the wild. The attack complexity is high, requiring network access without privileges or user interaction.

Mitigation Recommendations

According to the Red Hat advisory, applications using libkcapi should avoid one-shot symmetric cipher APIs for inputs larger than 64 KiB when continuous-message semantics are critical. Instead, they should use the streaming interface for processing large messages or ensure one-shot inputs remain below the internal chunking threshold to guarantee consistent IV application. No official patch is currently indicated; patch status is not yet confirmed — check the vendor advisory for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-qv62-qmw8-96h9
Osv Schema Version
1.4.0
Aliases
["CVE-2026-71225"]
Ecosystems
[]
Database Specific Severity
MODERATE
Cvss Version
3.1

Threat ID: 6a738529bf8831d5394f024a

Added to database: 08/05/2026, 18:47:05 UTC

Last enriched: 08/05/2026, 22:03:52 UTC

Last updated: 08/06/2026, 03:40:59 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses