I opened a ruby-advisory-db issue for the GCM nonce reuse issue in encryptor 2.0.0: https://github.com/rubysec/ruby-advisory-db/issues/305 The first step is to obtain a CVE. Are you interested in doing that? https://iwantacve.org If not I can get one on your behalf.