The Noise Java Project maintains a focused implementation of the Noise Protocol Framework, a cryptographic handshake specification designed for secure communication channels; its vulnerability footprint is correspondingly narrow and centered on the noise_java library itself. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Noise Java Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25022CRITICAL An issue was discovered in Noise-Java through 2020-08-27. AESGCMFallbackCipherState.encryptWithAd() allows out-of-bounds access. | Sep 4, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-25021CRITICAL An issue was discovered in Noise-Java through 2020-08-27. ChaChaPolyCipherState.encryptWithAd() allows out-of-bounds access. | Sep 4, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-25023CRITICAL An issue was discovered in Noise-Java through 2020-08-27. AESGCMOnCtrCipherState.encryptWithAd() allows out-of-bounds access. | Sep 4, 2020 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Noise Java Project.
Media articles that mention a CVE ID that affects a product developed by Noise Java Project — matched by CVE ID, not by vendor name.