More than 723,000 projects use cryptographic libraries (aes-js and pyaes) with insecure defaults.
According to Trail of Bits, the issue has been known to the developers since 2022 but was never fixed.
Carelessness versus craftsmanship in cryptography
Two popular AES libraries (aes-js and pyaes) provide dangerous default IVs that lead to key/IV reuse vulnerabilities affecting thousands of projects. One maintainer dismissed the issue, while strongSwan's maintainer exemplified proper security response by comprehensively fixing the vulnerability in their VPN management tool.
The Trail of Bits Blog (blog.trailofbits.com)
