Skip to content

Critical Security Fix in verifyWithMessage

Compare
Choose a tag to compare
@CMEONE CMEONE released this 15 Jun 17:24
· 43 commits to master since this release

CRITICAL: UPDATE IMMEDIATELY

This release resolves a critical vulnerability in the verifyWithMessage method of tEnvoyNaClSigningKey. Previously, verifyWithMessage would always return true for any signature that had a SHA-512 hash matching the SHA-512 hash of the message even if the signature was invalid.