{"id":"RUSTSEC-2026-0330","title":"Hybrid Encapsulation from Seed Panics on Short Seed","summary":"Hybrid Encapsulation from Seed Panics on Short Seed","severity":"none","vendor":"libcrux-kem","product":"libcrux-kem","ecosystem":"rust","affected":["libcrux-kem >= 0.0.0-0, < 0.0.10"],"patched":["libcrux-kem 0.0.10"],"published":"2026-09-28","updated":"2026-10-07","sourceUpdated":"2026-10-07T08:30:02.862241231Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/RUSTSEC-2026-0330","references":[{"url":"https://crates.io/crates/libcrux-kem"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0330.html"},{"url":"https://github.com/celabshq/libcrux/pull/1595"}],"tags":["osv","rust"],"ingestedAt":"2026-10-08T07:34:51.739Z","slug":"RUSTSEC-2026-0330","body":"## Overview\n\nFor a hybrid KEM public key of type `PublicKey::WingKemDraft06` or `PublicKey::X25519MlKem768Draft06`, the `PublicKey::encapsulate_derand` function would panic in an indexing operation on a seed input of length shorter than 32 bytes.\n\n# Impact\n\nApplications encapsulating with an attacker controlled seed value could be made to panic. Since the encapsulation seed should be considered a secret of the encapsulating party for the KEM to remain secure, an application should never take the seed value from a potentially attacker controlled source.\n\n# Mitigation\n\nWith release of version `0.0.10` of `libcrux-kem` this bug has been fixed and the serialization functions return `InvalidPrivateKey` and `InvalidPublicKey` errors on invalid input buffer lengths.\n\nWe recommend users upgrade to `libcrux-kem` version `0.0.10`.\n\n## Affected packages\n\n- `libcrux-kem >= 0.0.0-0, < 0.0.10`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `libcrux-kem 0.0.10`","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}