Scala Predictable Iv Nonce Source
Description
This vulnerability detector identifies cryptographic implementations that use predictable initialization vectors (IVs) or nonces in Scala code. Predictable IVs compromise encryption security by making encrypted data patterns observable and potentially allowing attackers to decrypt sensitive information or perform chosen-plaintext attacks.
Detection Strategy
• Scans Scala source code files that import the javax.crypto library for cryptographic operations
• Identifies cipher initialization calls (init method invocations) on Cipher objects created through Cipher.getInstance()
• Verifies the cipher is being configured for encryption mode (not decryption)
• Checks if an AlgorithmParameterSpec argument is provided that constructs predictable initialization vectors or nonces
• Reports vulnerability when encryption ciphers use deterministic or static IV/nonce values instead of cryptographically secure random values
Vulnerable code example
import javax.crypto.Cipher
import javax.crypto.spec.IvParameterSpec
import javax.crypto.spec.SecretKeySpec
def encrypt(data: Array[Byte], password: String): Array[Byte] = {
val cipher = Cipher.getInstance("AES/CBC/PKCS5Padding")
val key = new SecretKeySpec(password.getBytes, "AES")
...✅ Secure code example
import java.security.SecureRandom
import javax.crypto.Cipher
import javax.crypto.spec.IvParameterSpec
import javax.crypto.spec.SecretKeySpec
def encrypt(data: Array[Byte], password: String): Array[Byte] = {
val cipher = Cipher.getInstance("AES/CBC/PKCS5Padding")
val key = new SecretKeySpec(password.getBytes, "AES")...Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.