CVE-2026-6458
Last modified
CVE-2026-6458 is a medium-severity vulnerability rated 5.1/10 on the CVSS scale. Missing cryptographic step in Caliptra Core Firmware (aes_256_gcm_update module) results in an incorrect GCM authentication tag. When the streaming AES-256-GCM API is used with empty AAD, the hardware GHASH accumulator state is not saved after the first update call, causing the final tag to exclude the first batch of processed ciphertext. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
Missing cryptographic step in Caliptra Core Firmware (aes_256_gcm_update module) results in an incorrect GCM authentication tag. When the streaming AES-256-GCM API is used with empty AAD, the hardware GHASH accumulator state is not saved after the first update call, causing the final tag to exclude the first batch of processed ciphertext. Ciphertext produced by that call may be modified without the tag reflecting the change. This issue affects Core Runtime Firmware: from 2.0.0 through 2.0.1, 2.1.0.
Metrics
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Caliptra | Core Runtime Firmware | >= 2.0.0, <= 2.0.1; 2.1.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-6458?
How severe is CVE-2026-6458?
How do I fix CVE-2026-6458?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-64574In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64575In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64576In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-64577In the Linux kernel, the following vulnerability has been re…7.5
- CVE-2026-64578In the Linux kernel, the following vulnerability has been re…8.2
- CVE-2026-64579In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64580In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64581In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64582In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64583In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64584In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64585In the Linux kernel, the following vulnerability has been re…7.8
Are you affected by CVE-2026-6458?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
