← Back

Rhonabwy

rhonabwy

Vendor: Rhonabwy Project • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Rhonabwy Project
2Debian Linux
Rhonabwy
Jun 17, 2026
Feb 11, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops the comparison when the first difference is spotted in the two signatures. (The...Show more
In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops the comparison when the first difference is spotted in the two signatures. (The fix uses gnutls_memcmp, which has constant-time execution.)Show less
1Rhonabwy Project
1Rhonabwy
Jun 17, 2026
Aug 20, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Rhonabwy 0.9.99 through 1.1.x before 1.1.7 doesn't check the RSA private key length before RSA-OAEP decryption. This allows attackers to cause a Denial of Service via a crafted JWE (JSON Web Encryption) token.
1Rhonabwy Project
1Rhonabwy
Jun 17, 2026
Jul 13, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Rhonabwy before v1.1.5 was discovered to contain a buffer overflow via the component r_jwe_aesgcm_key_unwrap. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted JWE token.