@noble/ciphers is vulnerable to Improperly Implemented Security Check for Standard
10
Low Risk
Affected versions of the package accept fewer than the 8 bytes prescribed by OpenSSL for creating AES-GCM nonces. This improper nonce length could weaken the encryption and make it vulnerable to attacks.
You are affected if you are using a version that falls within the vulnerable range.
@noble/ciphers is vulnerable to Improperly Implemented Security Check for Standard in versions 0.4.0 - 0.6.0.
Upgrade the @noble/ciphers library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant