github.com
https://github.com/dajiaji/hpke-js CVE-2025-64767
CRITICAL
hpke-js reuses AEAD nonces
Record summary
CVE-2025-64767 has a selected CVSS score of 9.1 (critical).
Description
hpke-js is a Hybrid Public Key Encryption (HPKE) module built on top of Web Cryptography API. Prior to version 1.7.5, the public SenderContext Seal() API has a race condition which allows for the same AEAD nonce to be re-used for multiple Seal() calls. This can lead to complete loss of Confidentiality and Integrity of the produced messages. This issue has been patched in version 1.7.5.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 21, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
hpke-jsBrowse dajiaji / hpke-js | CVE List | < 1.7.5 | affected |
@hpke/coreBrowse npm / @hpke/core | GitHub Advisory | Before 1.7.5 · Fixed in 1.7.5 | affected |
References
5github.com
https://github.com/dajiaji/hpke-js/blob/b7fd3592c7c08660c98289d67c6bb7f891af75c4/packages/core/src/senderContext.ts github.com
https://github.com/dajiaji/hpke-js/commit/94a767c9b9f37ce48d5cd86f7017d8cacd294aaf github.comConfirmation
https://github.com/dajiaji/hpke-js/security/advisories/GHSA-73g8-5h73-26h4 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-64767