PatchSiren

ente CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM ente CVE published 2026-08-11

CVE-2026-73230

A vulnerability in Ente's 2of3 card format version 1 allowed for offline recovery of low-entropy or predictable secrets due to the cleartext storage of secret byte length and 32-bit FNV-1a checksum. This issue was fixed in version 2026.07.28. The vulnerability posed a medium-priority risk, allowing defenders to assess exposure and verify remediation to prevent potential offline attacks on low-entropy or p [truncated]