Due to improper input validation, a maliciously crafted input can cause a panic, due to incorrect nonce size. If this package is used to decrypt user supplied messages without checking the size of supplied nonces, this may be used as a vector for a denial of service attack.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2021-0102" }