CWE-323: Reusing a Nonce, Key Pair in Encryption
Nonces should be used for the present occasion and only once.
43 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-49952 — Discuz! X5.0 Authentication Bypass via dbbak.php Encryption Oracle
- CVE-2025-64767 — hpke-js reuses AEAD nonces
- CVE-2025-47345 — Reusing a Nonce, Key Pair in Encryption in Automotive Platform
- CVE-2026-30785 — RustDesk Encrypts Local Passwords with World-Readable Machine ID and Fixed Zero Nonce (XSalsa20-Poly1305)
- CVE-2026-3559 — Philips Hue Bridge HomeKit Accessory Protocol Static Nonce Authentication Bypass Vulnerability
- CVE-2026-59099 — Apereo CAS 7.3.0 < 8.0.0-RC6 - AES-GCM Nonce Reuse Information Disclosure
- CVE-2026-12205 — Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery
- CVE-2025-61739 — Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG reusing a nonce, key pair in encryption
- CVE-2026-13602 — Session takeover vulnerability
- CVE-2026-81020 — wolfEngine reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record
- CVE-2026-81019 — wolfProvider reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record
- CVE-2026-50577 — ePA 3.x Integration: AES-GCM Nonce Reuse via Frozen VAU Request Counter
- CVE-2026-21383 — Reusing a Nonce, Key Pair in Encryption in HLOS
- CVE-2024-36121 — netty-incubator-codec-ohttp's BoringSSLAEADContext Repeats Nonces
- CVE-2026-81341 — wolfEngine reuses the AES-CCM nonce on TLS 1.2 / DTLS 1.2 records
- CVE-2026-56369 — ImageMagick - Information Disclosure via AES-CTR Nonce Reuse in PasskeyEncipherImage
- CVE-2026-5446 — wolfSSL ARIA-GCM TLS 1.2/DTLS 1.2 GCM nonce reuse
- CVE-2026-3099 — Libsoup: libsoup: authentication bypass via digest authentication replay attack
- CVE-2024-41951 — PheonixAppAPI has visible Encoding Maps
- CVE-2026-45028 — Astro: Server island encrypted parameters vulnerable to cross-component replay
Recently published
- CVE-2026-81341 — wolfEngine reuses the AES-CCM nonce on TLS 1.2 / DTLS 1.2 records
- CVE-2026-81020 — wolfEngine reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record
- CVE-2026-81019 — wolfProvider reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record
- CVE-2026-50577 — ePA 3.x Integration: AES-GCM Nonce Reuse via Frozen VAU Request Counter
- CVE-2026-17578 — Kong Event Gateway AES-GCM nonce reuse due to missing key rotation enforcement
- CVE-2026-21383 — Reusing a Nonce, Key Pair in Encryption in HLOS
- CVE-2026-59099 — Apereo CAS 7.3.0 < 8.0.0-RC6 - AES-GCM Nonce Reuse Information Disclosure
- CVE-2026-13602 — Session takeover vulnerability
- CVE-2026-56369 — ImageMagick - Information Disclosure via AES-CTR Nonce Reuse in PasskeyEncipherImage
- CVE-2026-55967 — AES-GCM streaming APIs do not reject >64 GiB cumulative single messages, enabling counter wrap and keystream reuse
- CVE-2026-12205 — Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery
- CVE-2026-49952 — Discuz! X5.0 Authentication Bypass via dbbak.php Encryption Oracle
- CVE-2026-45028 — Astro: Server island encrypted parameters vulnerable to cross-component replay
- CVE-2026-5446 — wolfSSL ARIA-GCM TLS 1.2/DTLS 1.2 GCM nonce reuse
- CVE-2026-3559 — Philips Hue Bridge HomeKit Accessory Protocol Static Nonce Authentication Bypass Vulnerability
- CVE-2026-3099 — Libsoup: libsoup: authentication bypass via digest authentication replay attack
- CVE-2026-30785 — RustDesk Encrypts Local Passwords with World-Readable Machine ID and Fixed Zero Nonce (XSalsa20-Poly1305)
- CVE-2025-47345 — Reusing a Nonce, Key Pair in Encryption in Automotive Platform
- CVE-2025-61739 — Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG reusing a nonce, key pair in encryption
- CVE-2025-64767 — hpke-js reuses AEAD nonces