Cloak.Ciphers.AES.CTR encrypts with AES-256 in CTR mode and stores the key tag, the IV and the ciphertext with no MAC. decrypt/2 checks only the key tag and the minimum length before it returns the plaintext, and Cloak.Ciphers.Deprecated.AES.CTR decrypts the legacy format the same way. CTR is a stream cipher, so a value XORed into the stored ciphertext is XORed into the plaintext at the same offset. An attacker who can write to the encrypted store (for example through SQL injection or a compromised replica) and who knows or can guess a stored plaintext can replace it with any value of the same length. The application receives that value with no error.
This issue affects cloak: from 0.1.0-pre onward.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Configure the vault with Cloak.Ciphers.AES.GCM as the default cipher and re-encrypt existing values, for example with the cloak.migrate.ecto task from cloak_ecto. Then remove Cloak.Ciphers.AES.CTR and Cloak.Ciphers.Deprecated.AES.CTR from the vault configuration, so that ciphertext in the CTR format is no longer decrypted. AES-GCM authenticates the ciphertext and rejects modified values.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking vulnerability in danielberkompas cloak allows an attacker with write access to stored ciphertext to make it decrypt to a chosen value via bit flipping. Cloak.Ciphers.AES.CTR encrypts with AES-256 in CTR mode and stores the key tag, the IV and the ciphertext with no MAC. decrypt/2 checks only the key tag and the minimum length before it returns the plaintext, and Cloak.Ciphers.Deprecated.AES.CTR decrypts the legacy format the same way. CTR is a stream cipher, so a value XORed into the stored ciphertext is XORed into the plaintext at the same offset. An attacker who can write to the encrypted store (for example through SQL injection or a compromised replica) and who knows or can guess a stored plaintext can replace it with any value of the same length. The application receives that value with no error. This issue affects cloak: from 0.1.0-pre onward. | |
| Title | Cloak AES-CTR cipher lacks ciphertext authentication, allowing chosen-plaintext forgery by bit flipping | |
| First Time appeared |
Danielberkompas
Danielberkompas cloak |
|
| Weaknesses | CWE-649 | |
| CPEs | cpe:2.3:a:danielberkompas:cloak:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Danielberkompas
Danielberkompas cloak |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: EEF
Published:
Updated: 2026-10-06T11:40:42.775Z
Reserved: 2026-09-25T07:00:01.880Z
Link: CVE-2026-95105
Updated: 2026-10-06T11:40:24.528Z
Status : Received
Published: 2026-10-06T09:17:57.200
Modified: 2026-10-06T12:16:51.110
Link: CVE-2026-95105
No data.
OpenCVE Enrichment
Updated: 2026-10-06T12:00:15Z
-
CWE-649
Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking