> Without any third party dependencies (not even openssl or similar).
In your pursuit of "no dependencies", you made a classic blunder: making AES vulnerable to cache-timing attacks.
https://codeberg.org/ezcrypt/ezcrypt/src/commit/3268d71e80d3...
I'm not going to review the rest of your code. This is sufficient for me to recommend everyone run the other way screaming.