{"id":"CVE-2026-41244","summary":"Mojic: Observable Timing Discrepancy in HMAC Verification","details":"Mojic is a CLI tool to transform readable C code into an unrecognizable chaotic stream of emojis. Prior to 2.1.4, the CipherEngine uses a standard equality operator (!==) to verify the HMAC-SHA256 integrity seal during the decryption phase. This creates an Observable Timing Discrepancy (CWE-208), allowing a potential attacker to bypass the file integrity check via a timing attack. This vulnerability is fixed in 2.1.4.","aliases":["GHSA-wqq3-wfmp-v85g"],"modified":"2026-08-12T03:51:25.112577384Z","published":"2026-04-24T19:11:54.892Z","database_specific":{"cwe_ids":["CWE-208"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41244.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41244.json"},{"type":"ADVISORY","url":"https://github.com/notamitgamer/mojic/security/advisories/GHSA-wqq3-wfmp-v85g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41244"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/notamitgamer/mojic","events":[{"introduced":"0"},{"fixed":"676834bdc29c095c335d9449bd0954a05e8ddc21"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"fixed":"2.1.4"}]}}],"versions":["v2.1.2","v1.2.5","v1.0.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41244.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N"}]}