RUSTSEC-2026-0330None▾ SunlitHybrid Encapsulation from Seed Panics on Short Seed
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
For a hybrid KEM public key of type PublicKey::WingKemDraft06 or PublicKey::X25519MlKem768Draft06, the PublicKey::encapsulate_derand function would panic in an indexing operation on a seed input of length shorter than 32 bytes.
Applications encapsulating with an attacker controlled seed value could be made to panic. Since the encapsulation seed should be considered a secret of the encapsulating party for the KEM to remain secure, an application should never take the seed value from a potentially attacker controlled source.
With release of version 0.0.10 of libcrux-kem this bug has been fixed and the serialization functions return InvalidPrivateKey and InvalidPublicKey errors on invalid input buffer lengths.
We recommend users upgrade to libcrux-kem version 0.0.10.
libcrux-kem >= 0.0.0-0, < 0.0.10Upgrade to a patched release:
libcrux-kem 0.0.10Connected by shared product, vendor, weakness, or advisory.