crypto PoCs
subscribe (RSS)Proof-of-concept research filed under the crypto category.
Entries
3
in crypto
CISA KEV
0
exploited in the wild
Ransomware
0
known campaign use
Unpatched
1
no vendor fix
Critical
1
33% of listed
Severity
Exploitation signals
Patch status
Date range
3 result(s)
- CVE-2025-59390 crypto CRITICAL 9.8
Apache Druid Kerberos Cookie-Signing Secret Recovery via ThreadLocalRandom Seed Inversion (CVE-2025-59390)
When Apache Druid's Kerberos authenticator is deployed without an explicit druid.auth.authenticator.kerberos.cookieSignatureSecret, Druid falls back to generating that secret using Java's ThreadLocalRandom, which is not cryptographically secure. Because…
Patched 2026-07-06 - CVE-2026-45091 crypto HIGH
sealed-env Unseal Token TOTP/Enterprise Secret Disclosure (CVE-2026-45091)
sealed-env's "unseal token" is structured like a JWT (header.payload.signature) but its payload embeds sensitive material — specifically a totpSecret / enterpriseSecret field — in plain base64url-encoded JSON with no additional protection beyond the…
Patched 2026-07-05 - CVE-2026-39031 crypto HIGH
Lansweeper lsrunase 2.0 / lsencrypt 2.0 — RC4 Password Recovery (CVE-2026-39031)
Lansweeper's lsrunase and lsencrypt 2.0 tools implement a reversible password "encryption" scheme built on RC4 with a key derived from an 8-character cleartext prefix (stored alongside the ciphertext) concatenated with a fixed 142-byte suffix hardcoded into…
Unverified 2026-07-05