Researchers demonstrated that a Java web application using a fixed AES-GCM nonce for every encryption under the same key could be subverted despite authentication-tag validation. The application encrypted predictable sequential note identifiers and reused the AES key value, YELLOW_SUBMARINE, as its GCM nonce, allowing an attacker to collect ciphertexts produced with the same nonce and recover candidate GCM authentication subkeys.
Using those values, the proof of concept generated a valid authentication tag for an attacker-chosen ciphertext, forged an encrypted note identifier, and retrieved another user’s note. AES-GCM requires a unique nonce for every operation using a given key; nonce reuse can both enable tag forgery and reveal XOR relationships between plaintexts. Organizations should ensure nonces are generated uniquely per key, are never derived as fixed application constants, and rotate affected keys where reuse may have occurred.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
A demonstrated Java pastebin-style application reused the AES key bytes as a fixed AES-GCM nonce for every note-ID encryption. Using two ciphertexts, the proof of concept recovered candidate GHASH authentication subkeys, forged a valid ciphertext and tag for a chosen note identifier, and retrieved another user's note despite tag validation.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.