Skip to content

(xmlsec-nss) Hardened key transport / key agreement size checks, improved KW/KDF performance via context caching and in-place scratch staging, and cleaned up dead code - #1387

Merged
lsh123 merged 1 commit into
masterfrom
nss-fixes-1
Oct 7, 2026

(xmlsec-nss) Hardened key transport / key agreement size checks, impr…

b045273
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL completed Oct 7, 2026 in 3s

1 configuration not found

Warning: Code scanning cannot determine the alerts introduced by this pull request, because 1 configuration present on refs/heads/master was not found:

Actions workflow (codeql.yml)

  • ❓  /language:javascript-typescript

View all branch alerts.

Annotations

Check failure on line 419 in src/nss/kw_des.c

See this annotation in the file changed.

Code scanning / CodeQL

Use of a broken or risky cryptographic algorithm High

This file makes use of a broken or weak cryptographic algorithm (specified by
invocation of macro XMLSEC_NSS_KW_DES3_CIPHER_MECH
).
This file makes use of a broken or weak cryptographic algorithm (specified by
invocation of macro CKM_DES3_CBC
).
This file makes use of a broken or weak cryptographic algorithm (specified by
invocation of macro XMLSEC_NSS_KW_DES3_CIPHER_MECH
).
This file makes use of a broken or weak cryptographic algorithm (specified by
invocation of macro CKM_DES3_CBC
).
This file makes use of a broken or weak cryptographic algorithm (specified by
invocation of macro XMLSEC_NSS_KW_DES3_CIPHER_MECH
).
This file makes use of a broken or weak cryptographic algorithm (specified by
invocation of macro CKM_DES3_CBC
).
This file makes use of a broken or weak cryptographic algorithm (specified by
invocation of macro XMLSEC_KW_DES3_IV_LENGTH
).
This file makes use of a broken or weak cryptographic algorithm (specified by
invocation of macro XMLSEC_KW_DES3_IV_LENGTH
).