Every CVE whose affected-product data names Google Tink Java, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (2)
CVE-2026-15432 — CVSS 5.9 (medium): When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time comparison. This…
CVE-2020-8929 — CVSS 5.3 (medium): A mis-handling of invalid unicode characters in the Java implementation of Tink versions prior to 1.5 allows an attacker to change the ID…