Executive brief
@hpke/core is a JavaScript cryptography library implementing the HPKE (Hybrid Public Key Encryption) standard. A race condition in the SenderContext.Seal() API allows concurrent encryption calls to reuse the same nonce, completely compromising the confidentiality and integrity of encrypted messages. An attacker can decrypt messages or forge valid ciphertexts without knowledge of the encryption key.
Technical details
The vulnerability is a race condition (CWE-323) in the asynchronous SenderContext.Seal() implementation. The computeNonce() method can be invoked concurrently with identical sequence numbers, causing multiple seal() operations to generate and use the same AEAD nonce. Since AEAD schemes are cryptographically unsafe under nonce reuse, this completely breaks confidentiality and integrity guarantees. The attack requires only network access to an application using concurrent seal() calls; no authentication or user interaction is needed. The vulnerability affects all versions up to and including 1.7.4, with a fix available in version 1.7.5 or later that implements synchronization to ensure only one seal()/open() operation executes per context at a time.
Affected products
- @hpke core <= 1.7.4
Timeline
- 2025-11-20: disclosed
- 2025-11-20: patched: Fixed in version 1.7.5