CVE-2026-95105: Cloak AES-CTR cipher lacks ciphertext authentication, allowing chosen-plaintext forgery by bit flipping
Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking vulnerability in danielberkompas cloak allows an attacker with write access to stored ciphertext to make it decrypt to a chosen value via bit flipping.
Cloak.Ciphers.AES.CTR encrypts with AES-256 in CTR mode and stores the key tag, the IV and the ciphertext with no MAC. decrypt/2 checks only the key tag and the minimum length before it returns the plaintext, and Cloak.Ciphers.Deprecated.AES.CTR decrypts the legacy format the same way. CTR is a stream cipher, so a value XORed into the stored ciphertext is XORed into the plaintext at the same offset. An attacker who can write to the encrypted store (for example through SQL injection or a compromised replica) and who knows or can guess a stored plaintext can replace it with any value of the same length. The application receives that value with no error.
This issue affects cloak: from 0.1.0-pre onward.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments using cloak from 0.1.0-pre onward are affected when they use Cloak.Ciphers.AES.CTR. Data in the legacy Cloak.Ciphers.Deprecated.AES.CTR format is also affected.
What access does an attacker need to exploit this?
The attacker needs write access to stored ciphertext, such as through SQL injection or a compromised replica. They must also know or be able to guess the existing plaintext in order to replace it with a chosen value of the same length.
Will a modified encrypted value be detected during decryption?
No. Decryption checks only the key tag and minimum length, then returns the altered plaintext without an error; it does not verify ciphertext integrity.