CVE-2026-50577: CWE-323: Reusing a Nonce, Key Pair in Encryption in fbeta-GmbH ePA3-Service-OpenSource
CVE-2026-50577 is a vulnerability in fbeta-GmbH's ePA3-Service-OpenSource prior to version 1.3.0. The flaw involves reuse of AES-GCM nonce and key pairs due to a frozen client request counter, which leads to repeated nonces in encrypted responses. This allows an attacker to recover XORs of plaintexts and potentially sensitive patient health data. Additionally, the vulnerability enables recovery of the GHASH authentication key via the Joux forbidden attack, permitting message forgery and injection of malicious responses. The issue also weakens replay and ordering validation by failing to maintain the last response counter. The vulnerability is fixed in version 1.3.0.
AI Analysis
Technical Summary
The ePA 3.x Integration component of fbeta-GmbH's ePA3-Service-OpenSource prior to version 1.3.0 improperly handles the request_counter in app/vau/VAUProtokoll.py, causing reuse of AES-GCM nonce and key pairs across server responses. This cryptographic misuse allows a network attacker who captures repeated ciphertexts to recover the XOR of plaintext messages, leveraging predictable HTTP headers and JSON fields to extract sensitive patient health records. Furthermore, repeated nonces facilitate recovery of the GHASH authentication key through the Joux forbidden attack, enabling the attacker to forge AES-GCM messages and inject malicious responses. The response-counter check also fails to update last_response_counter, weakening protections against replay and message ordering attacks. The vulnerability is resolved in version 1.3.0.
Potential Impact
An attacker capable of intercepting network traffic can exploit nonce reuse in AES-GCM encryption to recover sensitive plaintext data, including patient health records. The vulnerability also allows recovery of the GHASH authentication key, enabling message forgery and injection of malicious responses. Additionally, weakened replay and ordering validation may allow attackers to replay or reorder messages undetected. This compromises confidentiality and integrity of the affected system's communications.
Mitigation Recommendations
This vulnerability is fixed in ePA3-Service-OpenSource version 1.3.0. Users should upgrade to version 1.3.0 or later to remediate the issue. No other mitigation is indicated by the vendor advisory.
CVE-2026-50577: CWE-323: Reusing a Nonce, Key Pair in Encryption in fbeta-GmbH ePA3-Service-OpenSource
Description
CVE-2026-50577 is a vulnerability in fbeta-GmbH's ePA3-Service-OpenSource prior to version 1.3.0. The flaw involves reuse of AES-GCM nonce and key pairs due to a frozen client request counter, which leads to repeated nonces in encrypted responses. This allows an attacker to recover XORs of plaintexts and potentially sensitive patient health data. Additionally, the vulnerability enables recovery of the GHASH authentication key via the Joux forbidden attack, permitting message forgery and injection of malicious responses. The issue also weakens replay and ordering validation by failing to maintain the last response counter. The vulnerability is fixed in version 1.3.0.
CVSS v3.1
Score 7.4high
Affected software
fbeta-GmbH
ePA3-Service-OpenSource
pkg:github/fbeta-gmbh/ePA3-Service-OpenSourceRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The ePA 3.x Integration component of fbeta-GmbH's ePA3-Service-OpenSource prior to version 1.3.0 improperly handles the request_counter in app/vau/VAUProtokoll.py, causing reuse of AES-GCM nonce and key pairs across server responses. This cryptographic misuse allows a network attacker who captures repeated ciphertexts to recover the XOR of plaintext messages, leveraging predictable HTTP headers and JSON fields to extract sensitive patient health records. Furthermore, repeated nonces facilitate recovery of the GHASH authentication key through the Joux forbidden attack, enabling the attacker to forge AES-GCM messages and inject malicious responses. The response-counter check also fails to update last_response_counter, weakening protections against replay and message ordering attacks. The vulnerability is resolved in version 1.3.0.
Potential Impact
An attacker capable of intercepting network traffic can exploit nonce reuse in AES-GCM encryption to recover sensitive plaintext data, including patient health records. The vulnerability also allows recovery of the GHASH authentication key, enabling message forgery and injection of malicious responses. Additionally, weakened replay and ordering validation may allow attackers to replay or reorder messages undetected. This compromises confidentiality and integrity of the affected system's communications.
Mitigation Recommendations
This vulnerability is fixed in ePA3-Service-OpenSource version 1.3.0. Users should upgrade to version 1.3.0 or later to remediate the issue. No other mitigation is indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-04T21:34:34.427Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a849468c6e8be03328570f0
Added to database: 08/18/2026, 17:20:40 UTC
Last enriched: 09/11/2026, 21:18:19 UTC
Last updated: 10/02/2026, 14:46:08 UTC
Views: 68
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.