THREAT OPS › Threat News › [NVD] CVE-2026-75803 (CRITICAL 9.1) — Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty
ciphertext can report success without verifying the supplied authentication
tag when the operation is finalized by calling the EVP_Cipher() function.
Impact summary: Applications calling EVP_Cipher() on an emp
[NVD] CVE-2026-75803 (CRITICAL 9.1) — Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function. Impact summary: Applications calling EVP_Cipher() on an emp
CVE-2026-75803 CVSS: 9.1 CRITICAL Published: 2026-08-25T13:19:29.570
Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function.
Impact summary: Applications calling EVP_Cipher() on an empty ciphertext and expecting the call to check the
Indicators of compromise
- CVE-2026-75803cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-75803