---
id: RUSTSEC-2026-0238
aliases:
  - GHSA-h9f2-fgp8-vc4h
title: Low-level GCM ignores the operation nonce
summary: Low-level GCM ignores the operation nonce
severity: none
vendor: dcrypt-algorithms
product: dcrypt-algorithms
ecosystem: rust
affected:
  - 'dcrypt-algorithms >= 0.0.0-0, < 2.0.0'
patched:
  - dcrypt-algorithms 2.0.0
published: '2026-08-09'
updated: '2026-08-09'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/RUSTSEC-2026-0238'
references:
  - url: 'https://crates.io/crates/dcrypt-algorithms'
  - url: 'https://rustsec.org/advisories/RUSTSEC-2026-0238.html'
  - url: >-
      https://github.com/ioi-foundation/dcrypt/security/advisories/GHSA-h9f2-fgp8-vc4h
  - url: >-
      https://github.com/ioi-foundation/dcrypt/commit/c99cc86f0ee353010cd202cbcd2c310371b0bbb8
  - url: 'https://github.com/ioi-foundation/dcrypt/releases/tag/v2.0.0'
tags:
  - osv
  - rust
ingestedAt: '2026-08-09T19:16:06.050Z'
---

## Overview

In all published versions of `dcrypt-algorithms` before 2.0.0, the low-level
`Gcm` builder required an operation nonce but derived `J0` from the nonce
captured by the original `Gcm` constructor. Multiple operations could therefore
silently reuse a nonce even when callers supplied distinct values, compromising
confidentiality and authenticity under an affected key.

Version 2.0.0 makes `Gcm` key-only and passes the operation nonce through IV
derivation, encryption, and decryption. It also corrects non-96-bit IV
processing, rejects tags shorter than 96 bits, and enforces counter limits.
Applications must upgrade, identify affected keys, rotate them, and re-encrypt
affected data; updating the implementation cannot restore security after nonce
reuse.

## Affected packages

- `dcrypt-algorithms >= 0.0.0-0, < 2.0.0`

## Remediation

Upgrade to a patched release:

- `dcrypt-algorithms 2.0.0`
