Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Zhiyuan Zhang

Researcher fromUniversity of Melbourne, Max Planck Institute for Security and Privacy
#41725of 56,336
6.9Total CVSS
Vulnerabilities · 2
Low
1
Medium
1
PT-2025-50637
1.0
2025-12-11
Wolfssl · Wolfssl · CVE-2025-13912
**Name of the Vulnerable Software and Affected Versions** wolfSSL versions prior to 5.8.4 **Description** Certain constant-time implementations within wolfSSL may be altered by LLVM optimizations into non-constant-time binaries. This transformation can introduce observable timing discrepancies, potentially leading to information disclosure through timing side-channel attacks. **Recommendations** Update to wolfSSL version 5.8.4 or later.
PT-2025-29131
5.9
2025-07-10
Liboqs · Liboqs · CVE-2025-52473
Name of the Vulnerable Software and Affected Versions: liboqs versions prior to 0.14.0 Description: liboqs is a C-language cryptographic library providing post-quantum cryptography algorithm implementations. Secret-dependent branches were identified in the HQC key encapsulation mechanism reference implementation when compiled with Clang at optimization levels above -O0. A proof-of-concept local attack exploits this secret-dependent information to recover the entire secret key. Recommendations: Update to version 0.14.0 or later.