Skip to content

Conversation

@sashaodessa
Copy link

The RPC subscription ID generator uses math/rand with a deterministic seed, making subscription IDs predictable. An attacker who observes a few subscription IDs can reconstruct the generator state and predict future IDs, potentially hijacking or interfering with other clients' subscriptions.

@sashaodessa sashaodessa requested a review from fjl as a code owner November 27, 2025 21:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant