PT-2026-78416 · Unknown · Libcrux-Ed25519+2

CVE-2026-76234

·

Published

2026-01-26

·

Updated

2026-08-21

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libcrux-ecdh versions prior to 0.0.6 libcrux-ed25519 versions prior to 0.0.6 libcrux-psq versions prior to 0.0.7
Description Cryptographic implementation bugs exist across multiple components. In libcrux-ecdh, length and clamping were not properly checked during X25519 secret validation, and the clamping check for imported X25519 secret keys was broken. In libcrux-ed25519, a duplicated clamping step occurred during key generation. Additionally, libcrux-psq experienced a panic instead of propagating an AEADError, which is an error related to Authenticated Encryption with Associated Data (AEAD).
Recommendations Update libcrux-ecdh to version 0.0.6 or later. Update libcrux-ed25519 to version 0.0.6 or later. Update libcrux-psq to version 0.0.7 or later.

Exploit

Fix

Use of a Broken Cryptographic Algorithm

Improper Verification of Cryptographic Signature

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76234
GHSA-435G-FCV3-8J26
RUSTSEC-2026-0023
RUSTSEC-2026-0024
RUSTSEC-2026-0025
RUSTSEC-2026-0026

Affected Products

Libcrux-Ecdh
Libcrux-Ed25519
Libcrux-Psq