Duplicate Advisory: Improper Verification of Cryptographic Signature
Critical severity
GitHub Reviewed
Published
Jun 21, 2021
to the GitHub Advisory Database
•
Updated Jan 23, 2026
Withdrawn
This advisory was withdrawn on Jan 23, 2026
Description
Published by the National Vulnerability Database
Jun 16, 2021
Reviewed
Jun 17, 2021
Published to the GitHub Advisory Database
Jun 21, 2021
Withdrawn
Jan 23, 2026
Last updated
Jan 23, 2026
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-7r96-8g3x-g36m. This link is maintained to preserve external references.
Original Description
tEnvoy contains the PGP, NaCl, and PBKDF2 in node.js and the browser (hashing, random, encryption, decryption, signatures, conversions), used by TogaTech.org. In versions prior to 7.0.3, the
verifyWithMessagemethod oftEnvoyNaClSigningKeyalways returnstruefor any signature that has a SHA-512 hash matching the SHA-512 hash of the message even if the signature was invalid. This issue is patched in version 7.0.3. As a workaround: Intenvoy.jsunder theverifyWithMessagemethod definition within thetEnvoyNaClSigningKeyclass, ensure that the return statement call tothis.verifyends in.verified.References