Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CryptX versions before 0.088_001 for Perl compare AEAD authentication tags in non-constant time in the streaming decrypt_done path. The decrypt_done($tag) form compares it against the computed tag with memNE (memcmp() != 0), which short-circuits on the first differing byte, so its run time depends on the number of matching leading bytes. This affects all five AEAD modes: GCM, CCM, ChaCha20Poly1305, EAX and OCB. The one-shot *_decrypt_verify helpers are unaffected; they verify the tag inside libtomcrypt with a constant-time comparison. The timing difference is a tag-verification oracle. An attacker who can submit many candidate tags for the same nonce, ciphertext and associated data while measuring the timing precisely enough may recover the expected tag byte by byte and forge a message that verifies. Join the discussion | CVE Database V5 | 06/29/2026, 20:42:14 UTC Added: 06/29/2026, 21:06:37 UTC |
CryptX versions prior to 0.088_001 for Perl contain a stack-based buffer overflow vulnerability in four AEAD decrypt_verify helper functions. These functions copy an attacker-controlled authentication tag into a fixed 144-byte stack buffer without validating the tag length, allowing an overflow if the tag is longer. The issue affects gcm_decrypt_verify, ccm_decrypt_verify, chacha20poly1305_decrypt_verify, and eax_decrypt_verify XS routines. Version 0.088 introduced a clamp to gcm_decrypt_verify, and 0.088_001 added clamps to the other three functions to prevent this overflow. No official patch or remediation guidance is currently documented in the vendor advisory or patch links. Join the discussion | CVE Database V5 | 05/28/2026, 14:13:19 UTC Added: 05/28/2026, 15:33:38 UTC |
0 CryptX versions before 0.088 for Perl contain a vulnerability where the Crypt::PK pseudo-random number generator (PRNG) state is not reseeded after a process fork. This causes child processes to share identical PRNG states, leading to identical outputs in cryptographic operations such as key generation and signing. Specifically, ECDSA or DSA signatures generated by different processes can leak the private key due to nonce reuse. This affects preforking services like the Starman web server that load Crypt::PK::* objects before forking. The vulnerability has a high severity with a CVSS score of 7.5. Join the discussion | CVE Database V5 | 04/23/2026, 07:29:26 UTC Added: 04/23/2026, 07:52:52 UTC |
Showing 1 to 3 of 3 results