Bandoche has a narrow vulnerability footprint centered on pypinksign, a cryptographic signing library where the observed weakness involves use of insufficiently random values in cryptographic operations. Treat this as a focused vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bandoche over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-48056HIGH PyPinkSign v0.5.1 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerability can lead to the disclosure of information and communicat | Nov 16, 2023 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bandoche.
Media articles that mention a CVE ID that affects a product developed by Bandoche — matched by CVE ID, not by vendor name.