Commit Detail
Commit dca4887
Zero EdDSA private key material on stack after use Stack buffers containing Ed25519/X25519 private key bytes were not zeroed after use. In the JWK export path, `rawPrivateKey` held the 32-byte private key on the stack and was never cleansed. In the keygen path, `rawPrivateKey` held the generated private key and persisted on the stack after the EVP_PKEY was constructed. Add `OPENSSL_cleanse` to zero private key buffers: - JWK export: inline cleanse after base64url encoding - Keygen: `KJ_DEFER(OPENSSL_cleanse(...))` to ensure zeroing even if key construction throws
Files changed
1 file changed~1 modified