VYPR

rpm package

opensuse/gopass&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/gopass&distro=openSUSE%20Tumbleweed

Vulnerabilities (3)

  • CVE-2026-1229CriFeb 24, 2026
    affected < 1.17.0-1.1fixed 1.17.0-1.1

    The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signing relying on this curve are not affected. The bug was fixed in v1.6.3 https://

  • CVE-2026-26958LowFeb 19, 2026
    affected < 1.17.0-1.1fixed 1.17.0-1.1

    filippo.io/edwards25519 is a Go library implementing the edwards25519 elliptic curve with APIs for building cryptographic primitives. In versions 1.1.0 and earlier, MultiScalarMult produces invalid results or undefined behavior if the receiver is not the identity point. If (*Poin

  • CVE-2024-45337CriDec 12, 2024
    affected < 1.15.16-1.1fixed 1.15.16-1.1

    Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that