CVE-2026-6092

When HAVE_ENCRYPT_THEN_MAC is configured, the implementation could fall back to MAC-then-Encrypt rather than enforcing Encrypt-then-MAC.

Scoring

Severity
LOW
CVSS base score
2.1
CVSS vector
CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/U:Clear
EPSS probability
0.38%
CWE
CWE-757
Published
2026-06-25
Last modified
2026-06-26

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs