From ca3494a4cf7b0c34448f153c541a78de947cabc9 Mon Sep 17 00:00:00 2001 From: Rowan Date: Sun, 26 Jul 2026 18:11:09 -0400 Subject: [PATCH] SECURITY.md: link the published advisory GHSA-3x95-24j9-7448 was published 2026-07-26 for the nonce-reuse issue this section already described. Linking it because an advisory that cannot be found from the repo is half-wasted -- SECURITY.md is where someone checking this library actually looks. CVE requested, assignment pending; it gets added here when GitHub's CNA assigns. Co-Authored-By: Claude Opus 5 --- SECURITY.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/SECURITY.md b/SECURITY.md index b950f15..debdb09 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -43,6 +43,8 @@ affects every implementation of netcode rather than one. ## Known issue: nonce reuse between global and per-client packets (fixed in 1.4.0) +**Advisory: [GHSA-3x95-24j9-7448](https://github.com/mas-bandwidth/netcode/security/advisories/GHSA-3x95-24j9-7448)** (published 2026-07-26; a CVE has been requested and is pending assignment). + **Affected: netcode 1.3.5 and earlier. Fixed in 1.4.0.** Global packets (connection challenge, connection denied) encrypt with the same