{"id":"GO-2023-2163","summary":"Curve KeyPairs fail to encrypt in github.com/nats-io/nkeys","details":"Curve KeyPairs always use the same (all-zeros) key to encrypt data, and provide no security.","aliases":["BIT-nats-2023-46129","CVE-2023-46129","GHSA-mr45-rx8q-wcm9"],"modified":"2026-02-04T02:17:32.973443Z","published":"2023-11-02T21:47:24Z","related":["CGA-gwj3-f8j3-cq37"],"database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2023-2163"},"references":[{"type":"ADVISORY","url":"https://github.com/nats-io/nkeys/security/advisories/GHSA-mr45-rx8q-wcm9"},{"type":"FIX","url":"https://github.com/nats-io/nkeys/commit/58fb9d69f42ea73fffad1d14e5914dc666f3daa1"}],"affected":[{"package":{"name":"github.com/nats-io/nkeys","ecosystem":"Go","purl":"pkg:golang/github.com/nats-io/nkeys"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.4.0"},{"fixed":"0.4.6"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/nats-io/nkeys","symbols":["ckp.Open","ckp.Seal","ckp.SealWithRand","decodePubCurveKey"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2023-2163.json"}}],"schema_version":"1.7.3","credits":[{"name":"Quentin Matillat (GitHub @tinou98)"}]}