PT-2026-78416 · Unknown · Libcrux-Ed25519+2
CVE-2026-76234
·
Published
2026-01-26
·
Updated
2026-08-21
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
libcrux-ecdh versions prior to 0.0.6
libcrux-ed25519 versions prior to 0.0.6
libcrux-psq versions prior to 0.0.7
Description
Cryptographic implementation bugs exist across multiple components. In libcrux-ecdh, length and clamping were not properly checked during X25519 secret validation, and the clamping check for imported X25519 secret keys was broken. In libcrux-ed25519, a duplicated clamping step occurred during key generation. Additionally, libcrux-psq experienced a panic instead of propagating an AEADError, which is an error related to Authenticated Encryption with Associated Data (AEAD).
Recommendations
Update libcrux-ecdh to version 0.0.6 or later.
Update libcrux-ed25519 to version 0.0.6 or later.
Update libcrux-psq to version 0.0.7 or later.
Exploit
Fix
Use of a Broken Cryptographic Algorithm
Improper Verification of Cryptographic Signature
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Libcrux-Ecdh
Libcrux-Ed25519
Libcrux-Psq