PT-2025-9525 · Aes-Gcm · Aes-Gcm

Thealtofwar

·

Published

2025-03-03

·

Updated

2025-03-04

·

CVE-2025-27498

CVSS v4.0

5.6

Medium

VectorAV:L/AC:H/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions aes-gcm versions prior to 0.4.3
Description The issue arises in the decrypt in place detached function, where the decrypted ciphertext is exposed even if the tag is incorrect. This occurs because the tag verification in the decrypt inplace function returns an error with the plaintext contents still in the buffer.
Recommendations For versions prior to 0.4.3, update to version 0.4.3 to resolve the issue.

Exploit

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-27498
GHSA-R38M-44FW-H886

Affected Products

Aes-Gcm