validate pre-key key-id ranges
details
- Finding IDs
- F-SIGNAL-SERVER-PREKEY-001
- Status
- likely fixed publicly (conditional mapping)
- Reported via
- private security contact
- Note
- public Signal-Server commits b7d455ed1140, b441fde2130, and fb84066f09df validate pre-key key-id ranges, enforce positive signed 32-bit ids, and align gRPC prekey rate-limit keys; these commits are present in tag v20260618.2.0. mapped to F-SIGNAL-SERVER-PREKEY-001 only if the private report concerned prekey key_id ranges / invalid ids / gRPC prekey limiter behavior; if it concerned depletion or last-resort semantics, an exact public fix was not observed.
F-SIGNAL-SERVER-PREKEY-001: Needs source detail. Key-ID validation and key-depletion semantics are different mechanisms; the public mapping does not resolve which applies. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-SIGNAL-SERVER-PREKEY-001
Security area (1seal assessment): Unclassified. The key-ID range patch is public, but the record also allows a different prekey-depletion interpretation. The exact finding-to-patch mapping must be resolved first. Reviewed 24 Sep 2026.