---
id: RUSTSEC-2026-0211
title: Non-constant time Authentication Tag Check in AES-GCM Decryption
summary: Non-constant time Authentication Tag Check in AES-GCM Decryption
severity: none
vendor: libcrux-aesgcm
product: libcrux-aesgcm
ecosystem: rust
affected:
  - libcrux-aesgcm >= 0.0.0-0
published: '2026-07-14'
updated: '2026-07-17'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/RUSTSEC-2026-0211'
references:
  - url: 'https://crates.io/crates/libcrux-aesgcm'
  - url: 'https://rustsec.org/advisories/RUSTSEC-2026-0211.html'
  - url: 'https://github.com/celabshq/libcrux/pull/1528'
tags:
  - osv
  - rust
ingestedAt: '2026-07-17T19:00:52.145Z'
---

## Overview

AES-GCM decryption used an implementation for checking the provided
authentication tag against the recomputed authentication tag that was
intended to be constant-time, but resulted in non-constant-time code
generation in certain circumstances.
Note that `libcrux-aesgcm` does not give guarantees on constant-time
code generation and possible mitigations must be considered
on a best-effort basis.

## Impact
Users of `libcrux-aesgcm` that expose a decryption oracle to an
attacker, which allows repeatedly querying for the same ciphertext
were at risk from timing side-channel attacks, depending on their
compilation environment. In the worst case, this could lead to
recovery of the recomputed authentication tag by the attacker, which
enables ciphertext forgery.

## Mitigation
Starting from version `0.0.9` (published as `libcrux-aes@v0.0.9`),
AES-GCM decryption uses a different, best-effort constant-time
implementation of the tag check, which has been checked to reliably
lead to constant time code generation, at the moment.

## Affected packages

- `libcrux-aesgcm >= 0.0.0-0`

## Remediation

Refer to the advisory for the patched release.
