HistoryEditJSON (OSV)

RUSTSEC-2026-0024

Incorrect X25519 clamping check rejects all secrets on import

Reported
Issued
Package
libcrux-psq (crates.io)
Type
Vulnerability
Aliases
References
CVSS Score
0 NONE
CVSS Details
Attack Complexity
Low
Attack Requirements
None
Attack Vector
Network
Privileges Required
None
Availability Impact to the Subsequent System
None
Confidentiality Impact to the Subsequent System
None
Integrity Impact to the Subsequent System
None
User Interaction
None
Availability Impact to the Vulnerable System
None
Confidentiality Impact to the Vulnerable System
None
Integrity Impact to the Vulnerable System
None
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N
Patched
  • >=0.0.7

Description

The latest releases of the libcrux-psq crate contains the following bug-fix:

#1301: Fix broken clamping check for imported X25519 secret keys

Advisory available under CC0-1.0 license.