{"id":"CVE-2025-27498","summary":"AEADs/ascon-aead: Plaintext exposed in decrypt_in_place_detached even on tag verification failure","details":"aes-gcm is a pure Rust implementation of the AES-GCM. In decrypt_in_place_detached, the decrypted ciphertext (which is the correct ciphertext) is exposed even if the tag is incorrect. This is because in decrypt_inplace in asconcore.rs, tag verification causes an error to be returned with the plaintext contents still in buffer. The vulnerability is fixed in 0.4.3.","aliases":["GHSA-r38m-44fw-h886"],"modified":"2026-08-12T03:51:36.846476043Z","published":"2025-03-03T16:52:02.750Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/27xxx/CVE-2025-27498.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-347"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/27xxx/CVE-2025-27498.json"},{"type":"ADVISORY","url":"https://github.com/RustCrypto/AEADs/security/advisories/GHSA-r38m-44fw-h886"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-27498"},{"type":"FIX","url":"https://github.com/RustCrypto/AEADs/commit/d1d749ba57e38e65b0e037cd744d0b17f7254037"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/rustcrypto/aeads","events":[{"introduced":"0"},{"fixed":"d1d749ba57e38e65b0e037cd744d0b17f7254037"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.4.3"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["ascon-aead-v0.4.2","chacha20poly1305-v0.11.0-pre.2","aes-siv-v0.8.0-pre.2","aes-gcm-v0.11.0-pre.2","aes-gcm-siv-v0.12.0-pre.2","chacha20poly1305-v0.11.0-pre.1","aes-gcm-v0.11.0-pre.1","aes-gcm-siv-v0.12.0-pre.1","aes-gcm-v0.11.0-pre.0","ocb3-v0.1.0","aes-gcm-v0.10.3","aes-gcm-v0.10.2","xsalsa20poly1305/v0.9.1","chacha20poly1305-v0.10.1","aes-gcm-siv-v0.11.1","aes-gcm-v0.10.1","xsalsa20poly1305-v0.9.0","chacha20poly1305-v0.10.0","aes-gcm-siv-v0.11.0","aes-gcm-v0.10.0","eax-v0.5.0","deoxys-v0.1.0","ccm-v0.5.0","aes-siv-v0.7.0","xsalsa20poly1305-v0.9.0-pre.2","chacha20poly1305-v0.10.0-pre.2","aes-gcm-v0.10.0-pre.2","aes-gcm-siv-v0.11.0-pre.2","xsalsa20poly1305-v0.9.0-pre.1","mgm-v0.5.0-pre.1","eax-v0.5.0-pre.1","deoxys-v0.1.0-pre.1","chacha20poly1305-v0.10.0-pre.1","ccm-v0.5.0-pre.1","aes-siv-v0.7.0-pre.1","aes-gcm-v0.10.0-pre.1","aes-gcm-siv-v0.11.0-pre.1","chacha20poly1305-v0.9.0","xsalsa20poly1305-v0.9.0-pre","aes-gcm-siv-v0.11.0-pre","aes-gcm-v0.10.0-pre","chacha20poly1305-v0.10.0-pre","mgm-v0.4.6","xsalsa20poly1305-v0.8.0","aes-gcm-siv-v0.10.3","chacha20poly1305-v0.8.2","aes-gcm-v0.9.4","mgm-v0.4.5","mgm-v0.4.4","xsalsa20poly1305-v0.7.2","mgm-v0.4.3","eax-v0.4.1","deoxys-v0.0.2","crypto_box-v0.6.1","chacha20poly1305-v0.8.1","ccm-v0.4.4","aes-siv-v0.6.2","aes-gcm-v0.9.3","aes-gcm-siv-v0.10.2","mgm-v0.4.2","ccm-v0.4.3","ccm-v0.4.2","ccm-v0.4.1","aes-siv-v0.6.1","deoxys-v0.0.1","aes-gcm-siv-v0.10.1","aes-gcm-v0.9.2","mgm-v0.4.1","aes-gcm-v0.9.1","mgm-v0.4.0","eax-v0.4.0","aes-siv-v0.6.0","aes-gcm-siv-v0.10.0","crypto_box-v0.6.0","xsalsa20poly1305-v0.7.1","ccm-v0.4.0","xsalsa20poly1305-v0.7.0","chacha20poly1305-v0.8.0","aes-gcm-v0.9.0","chacha20poly1305-v0.7.1","xsalsa20poly1305-v0.6.0","mgm-v0.3.0","eax-v0.3.0","crypto_box-v0.5.0","chacha20poly1305-v0.7.0","ccm-v0.3.0","aes-siv-v0.5.0","aes-gcm-v0.8.0","aes-gcm-siv-v0.9.0","eax-v0.2.0","xsalsa20poly1305-v0.5.0","crypto_box-v0.4.0","chacha20poly1305-v0.6.0","ccm-v0.2.0","aes-siv-v0.4.0","aes-gcm-v0.7.0","aes-gcm-siv-v0.8.0","crypto_box-v0.3.0","mgm-v0.2.1","mgm-v0.2.0","mgm-v0.1.1","mgm-v0.1.0","ccm-v0.1.0","xsalsa20poly1305-v0.4.2","xsalsa20poly1305-v0.4.1","chacha20poly1305-v0.5.1","crypto_box-v0.2.0","xsalsa20poly1305-v0.4.0","chacha20poly1305-v0.5.0","aes-siv-v0.3.0","aes-gcm-siv-v0.5.0","aes-gcm-v0.6.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-27498.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N"}]}