Rhonabwy Project is a small open-source project centered on the Rhonabwy WebAuthn library, which handles cryptographic authentication and credential validation in web applications. Its observed vulnerability exposure clusters around memory-safety issues such as classic buffer overflows, cryptographic algorithm weaknesses, and side-channel vulnerabilities in comparison logic—attack vectors characteristic of security-sensitive code operating at the authentication layer. Live severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rhonabwy Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-25714CRITICAL In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops the comparison when the first difference | Feb 11, 2024 | 9.8 | 26 | NO | NO |
CVE-2022-38493HIGH Rhonabwy 0.9.99 through 1.1.x before 1.1.7 doesn't check the RSA private key length before RSA-OAEP decryption. This allows attackers to cause a Denial of Service via a crafted JWE | Aug 20, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-32096HIGH Rhonabwy before v1.1.5 was discovered to contain a buffer overflow via the component r_jwe_aesgcm_key_unwrap. This vulnerability allows attackers to cause a Denial of Service (DoS) | Jul 13, 2022 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rhonabwy Project.
Media articles that mention a CVE ID that affects a product developed by Rhonabwy Project — matched by CVE ID, not by vendor name.