CWE-325: Missing Cryptographic Step
The product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.
54 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-22863 — Deno node:crypto doesn't finalize cipher
- CVE-2025-30147 — ALTBN128_ADD, ALTBN128_MUL, ALTBN128_PAIRING precompile functions do not check if points are on curve
- CVE-2026-4601 — Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.sig
- CVE-2026-76784 — Insufficient Cryptographic Protections in Local Device Communication Protocol on Multiple TP-Link Kasa Smart Home Devices
- CVE-2025-47383 — Missing Cryptographic Step in Data Modem
- CVE-2026-41395 — OpenClaw < 2026.3.28 - Webhook Replay via Query Parameter Reordering in Plivo V3
- CVE-2025-3938 — Missing Cryptographic Step
- CVE-2026-29142 — Plaintext secure-mail.html
- CVE-2025-5323 — fossasia open-event-server Mail Verification mail.py send_email_change_user_email reliance on obfuscation or encryption of security-relevant inputs without integrity checking
- CVE-2026-45445 — AES-OCB IV Ignored on EVP_Cipher() Path
- CVE-2026-49440 — Deno: Miller-Rabin Primality Test Allows Zero Rounds
- CVE-2025-58359 — frost-core: refresh shares with smaller min_signers will reduce group security
- CVE-2026-9266 — A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial
- CVE-2026-59776 — Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the v
- CVE-2025-69418 — Unauthenticated/unencrypted trailing bytes with low-level OCB function calls
- CVE-2026-48480 — netty-incubator-codec-ohttp OHttpVersionChunkDraft's Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation
- CVE-2026-25250 — EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step" associated with "Secure Boot
- CVE-2025-49600 — In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_verify may accept invalid signatures if hash computation fails and internal e
- CVE-2025-59339 — The Bastion ttyrec files are not signed after encryption by the osh-encrypt-rsync script
- CVE-2026-6458 — AES-256-GCM Authentication Tag Does Not Cover First Ciphertext Blocks When AAD Is Empty
Recently published
- CVE-2026-25250 — EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step" associated with "Secure Boot
- CVE-2026-76784 — Insufficient Cryptographic Protections in Local Device Communication Protocol on Multiple TP-Link Kasa Smart Home Devices
- CVE-2026-59776 — Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the v
- CVE-2026-6458 — AES-256-GCM Authentication Tag Does Not Cover First Ciphertext Blocks When AAD Is Empty
- CVE-2026-49440 — Deno: Miller-Rabin Primality Test Allows Zero Rounds
- CVE-2026-9266 — A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial
- CVE-2026-45446 — Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes
- CVE-2026-45445 — AES-OCB IV Ignored on EVP_Cipher() Path
- CVE-2026-42770 — FFC-DH Peer Validation Uses Attacker-Supplied q
- CVE-2026-0420 — Missing TLS certificate validation in NETGEAR's ReadyCloud client app
- CVE-2026-48480 — netty-incubator-codec-ohttp OHttpVersionChunkDraft's Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation
- CVE-2026-41395 — OpenClaw < 2026.3.28 - Webhook Replay via Query Parameter Reordering in Plivo V3
- CVE-2026-29142 — Plaintext secure-mail.html
- CVE-2026-4601 — Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.sig
- CVE-2025-47383 — Missing Cryptographic Step in Data Modem
- CVE-2025-69418 — Unauthenticated/unencrypted trailing bytes with low-level OCB function calls
- CVE-2026-22863 — Deno node:crypto doesn't finalize cipher
- CVE-2025-59339 — The Bastion ttyrec files are not signed after encryption by the osh-encrypt-rsync script
- CVE-2025-58359 — frost-core: refresh shares with smaller min_signers will reduce group security
- CVE-2025-49600 — In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_verify may accept invalid signatures if hash computation fails and internal e