@paulmillr: We’ve engaged @trailofbits, in collaboration with OpenAI, to audit noble-curves. No severe issues were found. A new rel…
摘要
Paul Miller announces that the noble-curves cryptography library was audited by Trail of Bits in collaboration with OpenAI, with no severe issues found, and a new v2.3 release is out.
查看缓存全文
缓存时间: 2026/08/12 16:29
We’ve engaged @trailofbits, in collaboration with OpenAI, to audit noble-curves.
No severe issues were found. A new release v2.3 is out.
Pretty cool that auditors are sending patches now! More info: https://t.co/nEGpUGUKYT
Dashboard · Patch the Planet · Trail of Bits
Source: https://trailofbits.com/patch-the-planet/dashboard cryptographylowDuplicate self-signed intermediates can cause exponential X.509 path-building CPU use —PRcryptographylowGCM delayed-tag decryption accepts sub-4-byte authentication tags —PRsequelizeundeterminedAP-03-L20: setSessionVariables() can make unsafe MySQL parsing attacker-reachable —PRsequelizeundeterminedAP-06-L01: Module-global syntax memoization retains attacker-selected paths —PRnoble-curvesinfoFROST DKG round-two retry is not bound to the first roster —PRnoble-curvesinfoFROST DKG round-two docs call raw private shares encrypted —PRnoble-curvesinfoRecovered ECDSA verification ignores the recovery byte and accepts noncanonical signature encodings —PRnoble-curvesinfoJubjub and BabyJubJub expose unsupported Edwards-to-Montgomery conversion helpers —PRnoble-curvesinfoEd448 toMontgomery uses the E448 birational map instead of the Ed448 4-isogeny —PRnoble-curveslowBLS verify accepts uncompressed signatures that the Signature codec rejects —PRnoble-curveslowBLS12-381 accepts modularly equivalent non-canonical encodings —PRcurlmedium--ssl overrides --ftp-ssl-control and permits plaintext FTP login fallback —PRcurllowProtocol-relative authority-changing redirects keep CURLOPT_PORT when absolute redirects clear it —PRcurlmediumRedirected transfers can reuse TLS state established without the configured pinned public key —PRcurllowNative CA trust can persist after an easy handle switches to custom CA material CVE-2026-11564PRcurlmediumFTP wildcard LIST parsing exposes stale symlink targets to callbacks —PRcurllowBare CR in response headers creates internal-parser and callback desync —PRcurllowCURLOPT_DISALLOW_USERNAME_IN_URL is not applied to CURLOPT_CURLU handles —PRcurllowWindows case-insensitive environments can make HTTP_PROXY satisfy curl’s http_proxy lookup —PRcurlmediumWindows SSPI SOCKS5 GSSAPI accepts negotiated protection that is not used —PRcurlmediumWindows SSPI GSSAPI unwrapped data is freed with the SSPI allocator —PRcurllowRedirected SigV4 URL credentials can inject HTTP/1.x request headers —PRcurlmediumServer NTLM state is not origin-bound for non-tunneled proxy reuse —PRcurlmediumNon-secure host-only cookies can shadow Secure domain cookies —PRcurlmediumSchannel sends origin client certificates to HTTPS proxies —PRcurllowSchannel automatic client certificates survive cross-origin redirects —PRcurllowMultiplexed non-tunneled HTTP/2 proxy reuse can store one origin’s cookie under another origin —PRcurllowRedirected Digest URL userinfo can inject HTTP/1.x request headers —PRcurlmediumCURL_POLL_REMOVE callback reentry can invalidate socket hash state still in use CVE-2026-9080PRcurlinfoReused easy handles keep stale .netrc contents after NETRC_FILE changes —PRcurlmediumDoH resolver sub-transfers do not inherit parent proxy policy —PRcurlinfoDoH inherits the Schannel automatic client-certificate option from the origin transfer —PRcrypto-bigintinfo[KEMs] Non-P-256 HPKE DHKEM helpers use the P-256 suite ID —PRcrypto-bigintlowFixed-width DER decode panics on oversized INTEGER values —PRcrypto-bigintinfoMontgomery bounded exponentiation panics with accidental index error for oversized exponent_bits —PRcrypto-bigintinfoInt serde impl is unreachable because Int does not implement Encoding —PRcrypto-bigintinfoZeroize can violate NonZero/Odd wrapper invariants —PRnginxhighHTTP/3 QPACK encoder stream reset leaves stale insert buffer pointer CVE-2026-42530PRaiohttplowHost-only cookies become domain cookies after CookieJar persistence CVE-2026-54279PRaiohttplowDigestAuthMiddleware uses credentials for redirect target challenges CVE-2026-54276PRaiohttpmediumC HTTP parser bypasses max_line_size across fragmented lines CVE-2026-54277PRaiohttpmediumWebSocket max_msg_size Is Enforced Only After Full Frame Buffering CVE-2026-54274PRaiohttplowTLS SNI/Hostname Verification Bypass Via Client Connection Reuse CVE-2026-54275PRaiohttplowHTTP/1 pipelined requests queue without a count limit CVE-2026-54273PRaiohttpmediumUnread compressed request bodies bypass client_max_size during cleanup CVE-2026-54278PRaiohttplowPayload response resources stay open after mid-body disconnect CVE-2026-54280PRgo-josemediumMissing protected JWE header causes panic after successful decryption CVE-2026-34986PRfreenginxmediumHTTP/3 DATA prefix can exceed its heap allocation —PRfreenginxlowmail auth HTTP can leave a stale session ctx after temp-pool destroy —PRfreenginxlowmail proxy leaves a stale upstream connection pointer after close —PRfreenginxlowgzip filter leaves `ctx->preallocated` stale after `ngx_pfree()` —PRfreenginxmediumHTTP Perl async callbacks store unrefcounted `SV`/`CV` pointers —PRfreenginxhighgRPC request serialization overflows on oversized HPACK :path —PRfreenginxmediumScript no-cacheable variable re-evaluation can overflow generated buffers —PRsimplexmqmediumIPv6 server URLs render ambiguous raw host and port pairs —PRsimplex-chatmedium[Bug]: Downloaded image attachments can be decoded at full dimensions and exhaust client memory —PRsimplex-chatmedium[Bug]: Android shared content size checks trust provider metadata before unbounded copy —PRansibleundeterminedsecurity: C# FailJson exceptions leak no_log values ——urllib3lowurllib3 accepts raw CR/LF in URL hosts and emits them in proxy CONNECT requests —PRansibleundeterminedsecurity: password lookup follows symlinks when creating secret files ——ansibleundeterminedsecurity: async_status jid escapes async directory ——ansibleundeterminedsecurity: apt_key keyring paths inject extra key imports ——ansibleundeterminedsecurity: file recurse follows symlinks outside managed directories ——kubernetes-clientundeterminedJDK HTTP client sends bodyless non-GET requests as GET —PRsqliteundeterminedLate vtab module registration leaves shadow tables writable —PRkubernetes-clientundeterminedKubeconfig `http://` proxy-url is bypassed for HTTPS clusters —PRkubernetes-clientundetermined`https://` proxy URL schemes are treated as plaintext HTTP proxies —PRsqliteundetermined`%!J` UTF-8 precision expansion narrows four-gigabyte input —PRsqliteundeterminedSide-effect `sqlite_log()` is treated as innocuous —PRsqliteundetermined`sqlite3_drop_modules()` races module hash iteration —PRsqliteundeterminedSerial type 10 smuggles virtual-table no-change value ——sqliteundeterminedjson_pretty() reads past malformed JSONB object payload —PRsqliteundetermined.archive extraction allows absolute sibling path escape —PRsqliteundeterminedCorrupt index cell pointer crosses page boundary —PRsqliteundeterminedMalformed UTF-8 precision in `%!s` allows oversized memcpy —PRsqliteundeterminedCrafted Rollback Journal Can Delete an Arbitrary File —PRsqliteundeterminedHeap buffer overflow in sqlite3ParseUri for over-1GiB file: URI filenames —PRsqliteundeterminedOdd UTF-16 prepare length reads past caller buffer —PRkubernetes-clientundeterminedFix CI auth safety bug —PRsigstorelowKey validity period not checked for verifications involving long-lived keys —PRnssundeterminedHeap Buffer Overflow in NSS Legacy libpkix HTTP OCSP Client —PRpythondotorglow[PTP-PYTHON-007] Bug: release-file APIs accept new HTTP python.org URLs —PRpythondotorgmedium[PTP-PYTHON-001] Bug: ReleaseFile sidecar URLs can point to different artifacts —PRrelease-toolslow[PTP-PYTHON-008] Bug: add_to_pydotorg can leave partial release-file metadata after post failure —PRborpmediumborp UpdateColumns cached plan bypasses column filter —PRborpmediumGenerated SQL does not escape identifier quote characters —PRpythondotorgmedium[PTP-PYTHON-004] Bug: inactive staff API keys still authorize v1 writes —PRpythondotorgmedium[PTP-PYTHON-003] Bug: v1 Tastypie writes accept staff sessions without API keys —PRpythondotorgmedium[PTP-PYTHON-005] Bug: v1 Tastypie accepts API keys in query strings —PRpythondotorgmedium[PTP-PYTHON-006] Bug: v1 Tastypie resources allow broad collection mutations —PRpythondotorglow[PTP-PYTHON-009] Bug: delete_by_release silently honors extra filters —PRrelease-toolsinfo[PTP-PYTHON-012] Bug: free-threaded Windows artifacts are skipped by add_to_pydotorg —PRpythondotorglow[PTP-PYTHON-014] Bug: custom 404 legacy link can point to an external URL —PRgo-josehighgo-jose VerifyMulti can return a victim kid for an attacker-signed JWS ——go-josemediumParseSigned strips whitespace before JSON parsing and can smuggle unprotected JWS headers —PRsimplex-chatmedium[Bug]: Desktop call localhost WebSocket accepts cross-origin browser control —PRsimplex-chatmedium[Bug]: WebRTC call switch leaves abandoned preview media active —PRsimplex-chathigh[Bug]: Relay short-link decompression can exhaust memory —PRsimplexmqmediumClient-selectable APNS test provider sends APNS bearer traffic to localhost —PRwarehouseinfoREADME sanitizer allows active input controls —PRwarehouseinfopip-audit release workflow exposes PyPI OIDC token before publish step —PRwarehouseinfoWarehouse can publish broadened Requires-Dist markers after packaging round trip —PRsimplex-chathigh[Bug]: Inbound group role changes allow admin owner promotion —PRsimplex-chatmedium[Bug]: Negative file invitations can bypass auto-receive and file-size gating —PRrustundeterminedrustc: unsafe checker skips `ExprKind::Reborrow { source }` and allows unsafe ops under `#![deny(unsafe_code)]` (`#![feature(reborrow)]`) —PRrustundeterminedrustc: `become` tail calls between `extern “rust-call”` fns can pass stale/uninitialized indirect tuple args at `-O` —PRrustundeterminedrustc: by-value `#[track_caller]` trait method called via `Box<dyn Trait>` uses a vtable shim that drops the caller-location ABI argument (`unsized_fn_params`) —PRsimplexmqlowXFTP CLI receive path allows sender-controlled filename traversal —PRsimplexmqmediumSNTRUP761 KEM bindings accept unchecked public key and ciphertext lengths —PRsimplexmqmediumSTM queue store LSET can hijack existing short-link ids —PRsimplexmqhighXFTP FNEW creates durable metadata before upload or quota reservation —PRsimplexmqlowScripted SMP installs enable HTTPS without provisioning web credentials —PRsimplexmqlowsimplex-servers-update writes release metadata before creating parent directory —PRsimplexmqhighXFTP redirected-description parser error reaches production innerHTML sink and can expose file secrets —PRsimplexmqmediumXFTP web host gate accepts any referenced current host but fetches first replicas —PRsimplexmqlowProduction XFTP web bundle logs DH secrets and decrypted chunk bytes —PRsimplex-chatlow[Bug]: Remote controller file upload path allows filename traversal —PRsimplex-chatmedium[Bug]: Postgres delivery pagination can redeliver group events —PRsimplex-chathigh[Bug]: Demoted admins keep a live group link that continues accepting joiners —PRsimplex-chathigh[Bug]: Demoted channel owners can republish stale owner metadata into short-link data —PRsimplex-chathigh[Bug]: Accepted senders can grow XFTP file descriptions without a total length or part-count limit before file acceptance —PRsimplex-chatmedium[Bug]: Chat tag and TTL APIs mutate chats by raw ID without user ownership checks —PRsimplex-chatlow[Bug]: Oversized relay delivery tasks can create durable empty delivery jobs —PRcrypto-bigintinfoUintRef slice copy length checks disappear in release builds —PRcrypto-bigintlowBoxedUint BitOrAssign drops high limbs from wider RHS —PRcrypto-bigintinfolimb::nlimbs overflows before rounding large bit counts —PRcrypto-bigintinfoUint div_exact panics on wide divisors with dividend-precision trailing zeros —PRcrypto-bigintinfoModulus-one edge cases need canonicalization or rejection —PRcrypto-bigintinfoUintRef bytes_precision returns limb count instead of byte count —PRcrypto-bigintlowMontyParams constant-time equality ignores mod_leading_zeros —PRurllib3lowAbsolute request targets include URL fragments —PRaiohttpmediumNumeric IPv4 host forms bypass aiohttp resolver policies —PRaiohttplowEnvironment Proxy Credentials Leak to Different Proxy After Redirect —PRwarehouselowpackaging DirectUrl credential stripping can leak password fragments —PRsimplex-chatundetermined[Bug]: Android service watchdog does not restart after normal teardown —PRwarehouseinfoREADME sanitizer ignores stricter policy overrides —PRzlibundeterminedTruncated gzip header name/comment reuse can over-read deflateSetHeader ——warehouseinfoLinehaul ingestor retries poison gzip objects indefinitely —PRwarehouseinfopipx: address zizmor findings in GitHub Actions —PRwarehouseinfotrove-classifiers release workflow exposes PyPI OIDC token before publish step —PRwarehouseinfopipx release workflow exposes PyPI OIDC token before publish step —PRwarehouseinfostdlib-list release workflow exposes PyPI OIDC token before publish step —PRwarehouseinfolinehaul release workflow exposes PyPI OIDC token before publish step —PRwarehouseinfoCI installs unpinned lint and test tooling from live PyPI —PRwarehouseundeterminedpypa/build: backend-path containment can allow sibling directories —PRpythondotorgundetermined[PTP-PYTHON-013] Bug: Fastly purge workflow executes path-derived keys in a secret-bearing shell —PR
相似文章
@paulmillr: 每周下载量,过去12个月:- 哈希库:增长4倍 => 每周4800万 - 曲线库:增长3倍 - 后量子密码库:增长95倍 两个趋势尤为突出:1. 高质量…
开源加密库的每周下载量增长:哈希库增长4倍(每周4800万),曲线库增长3倍,后量子密码库增长95倍。14个库的新自审计版本发布,带有安全升级。
@no_stp_on_snek:Nvidia 的 Nemotron 3.5 Lightning 行为分析。它捕获了一个技术负责人和四位审批者已经签字通过的认证漏洞……
对 Nvidia 的 Nemotron 3.5 Lightning 进行的行为审计发现其具有强大的完整性,捕获了所审查代码中的一处微妙认证漏洞,并通过了安全探针测试,同时指出了其在基于行为的诚实性方面存在盲点。
关于近期 Claude Code 质量报告的更新
Anthropic 发布了一份事后分析报告,回应近期关于 Claude Code 的质量反馈,识别并修复了三个问题,涉及推理努力程度默认值、会话状态管理和系统提示词,这些问题影响了 Sonnet 和 Opus 模型。
@mattpocockuk: Cursor 推出了一个 /thermo-nuclear-code-review,用于最严苛的 AI 代码审查。但它到底好不好?让我们深入探讨……
Cursor 推出了一项新的‘热核’代码审查功能,用于激进的 AI 代码审查。Matt Pocock 对其效果进行了评测。
@_mattata: Anthropic 发布了一个相当简洁的代码审计工具,用于识别具有潜在安全影响的漏洞。它…
Anthropic 发布了一个开源代码审计参考工具,用于使用 Claude 进行自主漏洞发现和修复,涵盖了 recon→find→triage→report→patch 流程,主要针对 C/C++ 内存漏洞。它是一个模板/参考实现,而非生产就绪产品,同时还提供名为 Claude Security 的托管选项。