MEDIUM

CVE-2025-69418

CVSS v3

4

MEDIUM

EPSS Score

0.0%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed in<br>cleartext on encryption and are not covered by the authentication tag,<br>allowing an attacker to read or tamper with those bytes without detection.<br><br>The low-level OCB encrypt and

Technical details

CVSS v3 Vector
3.1
Published
1/27/2026
Last Modified
2/2/2026

Frequently asked questions

What is CVE-2025-69418?

Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed in<br>cleartext on encryption and are not covered by the authentication tag,<br>allowing an attacker to read or tamper with those bytes without detection.<br><br>The low-level OCB encrypt and

Is CVE-2025-69418 actively exploited?

Active exploitation of CVE-2025-69418 has not been confirmed. The EPSS score is 0.0%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2025-69418?

CVE-2025-69418 has a CVSS v3 base score of 4 (MEDIUM severity), with vector string 3.1.

Is CVE-2025-69418 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.