CVE-2025-8556Low· 3.7▾ SunlitCIRCL-Fourq: Missing and wrong validation can lead to incorrect results
▾ Sunlit zone — Low / medium · no exploitation signal
impact 20.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.5%
The CIRCL implementation of FourQ fails to validate user-supplied low-order points during Diffie-Hellman key exchange, potentially allowing attackers to force the identity point and compromise session security.
Moreover, there is an incorrect point validation in ScalarMult can lead to incorrect results in the isEqual function and if a point is on the curve.
Version 1.6.1 (https://github.com/cloudflare/circl/tree/v1.6.1) mitigates the identified issues.
We acknowledge Alon Livne (Botanica Software Labs) for the reported findings.
github.com/cloudflare/circl < 1.6.1Upgrade to a patched release:
github.com/cloudflare/circl 1.6.1Connected by shared product, vendor, weakness, or advisory.
CVE-2023-1732Medium· 5.3Improper random reading in CIRCL
CVE-2021-3911Medium· 4.2Misconfigured IP address field in ROA leads to OctoRPKI crash
CVE-2022-3616Medium· 5.4OctoRPKI crashes when max iterations is reached
CVE-2021-3912Medium· 4.2OctoRPKI crashes when processing GZIP bomb returned via malicious repository
CVE-2021-3908Medium· 5.9Infinite certificate chain depth results in OctoRPKI running forever
CVE-2021-3761High· 7.5OctoRPKI lacks contextual out-of-bounds check when validating RPKI ROA maxLength values