Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wqq3-wfmp-v85g | Mojic: Observable Timing Discrepancy in HMAC Verification |
Mon, 27 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Notamitgamer
Notamitgamer mojic |
|
| Vendors & Products |
Notamitgamer
Notamitgamer mojic |
Fri, 24 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Apr 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mojic is a CLI tool to transform readable C code into an unrecognizable chaotic stream of emojis. Prior to 2.1.4, the CipherEngine uses a standard equality operator (!==) to verify the HMAC-SHA256 integrity seal during the decryption phase. This creates an Observable Timing Discrepancy (CWE-208), allowing a potential attacker to bypass the file integrity check via a timing attack. This vulnerability is fixed in 2.1.4. | |
| Title | Mojic: Observable Timing Discrepancy in HMAC Verification | |
| Weaknesses | CWE-208 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-24T19:59:59.355Z
Reserved: 2026-04-18T03:47:03.135Z
Link: CVE-2026-41244
Updated: 2026-04-24T19:59:56.082Z
Status : Deferred
Published: 2026-04-24T20:16:26.957
Modified: 2026-04-28T21:18:07.827
Link: CVE-2026-41244
No data.
OpenCVE Enrichment
Updated: 2026-04-28T13:45:06Z
Github GHSA