libcrux-sha3
Activity
- Latest release
- 2mo ago
- Total releases
- 24
- Cadence
- ~11 days
- Last 12 months
- 15
Details
- License
- Apache-2.0
- First release
- Jul 02, 2024
| Version | Released | |
|---|---|---|
0.0.10
unknown
|
0.0.10
unknown
Dependencies (9)
+ 1 more |
|
0.0.10-pre.1
unknown
2 CVEs
RUSTSEC-2026-0208
May 21, 2026
Potential Panic in AVX2 SHAKE-256
High
Network
Low
None
None
The AVX2-optimized implementation of SHAKE-256 intended for use in ML-KEM and ML-DSA would panic if the length of the output buffers was greater than 32 and not a multiple of 8, due to an out-of-bounds indexing operation. ImpactThis bug impacts users on AVX2 platforms that use the
MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0207
Apr 22, 2026
Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when
attempting to squeeze an output using multiple calls to ImpactThis bug impacts users that rely on this XOF API to squeeze output in
multiple calls where any of the calls request an output length that is
not divisible by MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev |
0.0.10-pre.1
unknown
Dependencies (9)
+ 1 more |
|
0.0.9
unknown
2 CVEs
RUSTSEC-2026-0208
May 21, 2026
Potential Panic in AVX2 SHAKE-256
High
Network
Low
None
None
The AVX2-optimized implementation of SHAKE-256 intended for use in ML-KEM and ML-DSA would panic if the length of the output buffers was greater than 32 and not a multiple of 8, due to an out-of-bounds indexing operation. ImpactThis bug impacts users on AVX2 platforms that use the
MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0207
Apr 22, 2026
Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when
attempting to squeeze an output using multiple calls to ImpactThis bug impacts users that rely on this XOF API to squeeze output in
multiple calls where any of the calls request an output length that is
not divisible by MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev |
0.0.9
unknown
Dependencies (9)
+ 1 more |
|
0.0.9-rc.1
unknown
2 CVEs
RUSTSEC-2026-0208
May 21, 2026
Potential Panic in AVX2 SHAKE-256
High
Network
Low
None
None
The AVX2-optimized implementation of SHAKE-256 intended for use in ML-KEM and ML-DSA would panic if the length of the output buffers was greater than 32 and not a multiple of 8, due to an out-of-bounds indexing operation. ImpactThis bug impacts users on AVX2 platforms that use the
MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0207
Apr 22, 2026
Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when
attempting to squeeze an output using multiple calls to ImpactThis bug impacts users that rely on this XOF API to squeeze output in
multiple calls where any of the calls request an output length that is
not divisible by MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev |
0.0.9-rc.1
unknown
Dependencies (9)
+ 1 more |
|
0.0.8
unknown
2 CVEs
RUSTSEC-2026-0208
May 21, 2026
Potential Panic in AVX2 SHAKE-256
High
Network
Low
None
None
The AVX2-optimized implementation of SHAKE-256 intended for use in ML-KEM and ML-DSA would panic if the length of the output buffers was greater than 32 and not a multiple of 8, due to an out-of-bounds indexing operation. ImpactThis bug impacts users on AVX2 platforms that use the
MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0207
Apr 22, 2026
Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when
attempting to squeeze an output using multiple calls to ImpactThis bug impacts users that rely on this XOF API to squeeze output in
multiple calls where any of the calls request an output length that is
not divisible by MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev |
0.0.8
unknown
Dependencies (9)
+ 1 more |
|
0.0.8-rc.1
unknown
3 CVEs
RUSTSEC-2026-0208
May 21, 2026
Potential Panic in AVX2 SHAKE-256
High
Network
Low
None
None
The AVX2-optimized implementation of SHAKE-256 intended for use in ML-KEM and ML-DSA would panic if the length of the output buffers was greater than 32 and not a multiple of 8, due to an out-of-bounds indexing operation. ImpactThis bug impacts users on AVX2 platforms that use the
MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0207
Apr 22, 2026
Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when
attempting to squeeze an output using multiple calls to ImpactThis bug impacts users that rely on this XOF API to squeeze output in
multiple calls where any of the calls request an output length that is
not divisible by MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
GHSA-q29p-9pfr-j652
RUSTSEC-2026-0074
Mar 26, 2026
libcrux-sha3: Incorrect output from SHAKE squeeze functions
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when attempting to squeeze more than ImpactThis bug impacts users that rely on this XOF API to squeeze more than MitigationStarting from version Fixed in
0.0.8
References Updated Sep 10, 2026 · Source: OSV.dev |
0.0.8-rc.1
unknown
Dependencies (10)
+ 2 more |
|
0.0.7
unknown
3 CVEs
RUSTSEC-2026-0208
May 21, 2026
Potential Panic in AVX2 SHAKE-256
High
Network
Low
None
None
The AVX2-optimized implementation of SHAKE-256 intended for use in ML-KEM and ML-DSA would panic if the length of the output buffers was greater than 32 and not a multiple of 8, due to an out-of-bounds indexing operation. ImpactThis bug impacts users on AVX2 platforms that use the
MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0207
Apr 22, 2026
Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when
attempting to squeeze an output using multiple calls to ImpactThis bug impacts users that rely on this XOF API to squeeze output in
multiple calls where any of the calls request an output length that is
not divisible by MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
GHSA-q29p-9pfr-j652
RUSTSEC-2026-0074
Mar 26, 2026
libcrux-sha3: Incorrect output from SHAKE squeeze functions
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when attempting to squeeze more than ImpactThis bug impacts users that rely on this XOF API to squeeze more than MitigationStarting from version Fixed in
0.0.8
References Updated Sep 10, 2026 · Source: OSV.dev |
0.0.7
unknown
Dependencies (10)
+ 2 more |
|
0.0.7-pre.2
unknown
3 CVEs
RUSTSEC-2026-0208
May 21, 2026
Potential Panic in AVX2 SHAKE-256
High
Network
Low
None
None
The AVX2-optimized implementation of SHAKE-256 intended for use in ML-KEM and ML-DSA would panic if the length of the output buffers was greater than 32 and not a multiple of 8, due to an out-of-bounds indexing operation. ImpactThis bug impacts users on AVX2 platforms that use the
MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0207
Apr 22, 2026
Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when
attempting to squeeze an output using multiple calls to ImpactThis bug impacts users that rely on this XOF API to squeeze output in
multiple calls where any of the calls request an output length that is
not divisible by MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
GHSA-q29p-9pfr-j652
RUSTSEC-2026-0074
Mar 26, 2026
libcrux-sha3: Incorrect output from SHAKE squeeze functions
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when attempting to squeeze more than ImpactThis bug impacts users that rely on this XOF API to squeeze more than MitigationStarting from version Fixed in
0.0.8
References Updated Sep 10, 2026 · Source: OSV.dev |
0.0.7-pre.2
unknown
Dependencies (10)
+ 2 more |
|
0.0.7-pre.1
unknown
3 CVEs
RUSTSEC-2026-0208
May 21, 2026
Potential Panic in AVX2 SHAKE-256
High
Network
Low
None
None
The AVX2-optimized implementation of SHAKE-256 intended for use in ML-KEM and ML-DSA would panic if the length of the output buffers was greater than 32 and not a multiple of 8, due to an out-of-bounds indexing operation. ImpactThis bug impacts users on AVX2 platforms that use the
MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0207
Apr 22, 2026
Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when
attempting to squeeze an output using multiple calls to ImpactThis bug impacts users that rely on this XOF API to squeeze output in
multiple calls where any of the calls request an output length that is
not divisible by MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
GHSA-q29p-9pfr-j652
RUSTSEC-2026-0074
Mar 26, 2026
libcrux-sha3: Incorrect output from SHAKE squeeze functions
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when attempting to squeeze more than ImpactThis bug impacts users that rely on this XOF API to squeeze more than MitigationStarting from version Fixed in
0.0.8
References Updated Sep 10, 2026 · Source: OSV.dev |
0.0.7-pre.1
unknown
Dependencies (10)
+ 2 more |
|
0.0.6
unknown
3 CVEs
RUSTSEC-2026-0208
May 21, 2026
Potential Panic in AVX2 SHAKE-256
High
Network
Low
None
None
The AVX2-optimized implementation of SHAKE-256 intended for use in ML-KEM and ML-DSA would panic if the length of the output buffers was greater than 32 and not a multiple of 8, due to an out-of-bounds indexing operation. ImpactThis bug impacts users on AVX2 platforms that use the
MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0207
Apr 22, 2026
Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when
attempting to squeeze an output using multiple calls to ImpactThis bug impacts users that rely on this XOF API to squeeze output in
multiple calls where any of the calls request an output length that is
not divisible by MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
GHSA-q29p-9pfr-j652
RUSTSEC-2026-0074
Mar 26, 2026
libcrux-sha3: Incorrect output from SHAKE squeeze functions
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when attempting to squeeze more than ImpactThis bug impacts users that rely on this XOF API to squeeze more than MitigationStarting from version Fixed in
0.0.8
References Updated Sep 10, 2026 · Source: OSV.dev |
0.0.6
unknown
Dependencies (10)
+ 2 more |
|
0.0.6-pre.1
unknown
3 CVEs
RUSTSEC-2026-0208
May 21, 2026
Potential Panic in AVX2 SHAKE-256
High
Network
Low
None
None
The AVX2-optimized implementation of SHAKE-256 intended for use in ML-KEM and ML-DSA would panic if the length of the output buffers was greater than 32 and not a multiple of 8, due to an out-of-bounds indexing operation. ImpactThis bug impacts users on AVX2 platforms that use the
MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0207
Apr 22, 2026
Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when
attempting to squeeze an output using multiple calls to ImpactThis bug impacts users that rely on this XOF API to squeeze output in
multiple calls where any of the calls request an output length that is
not divisible by MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
GHSA-q29p-9pfr-j652
RUSTSEC-2026-0074
Mar 26, 2026
libcrux-sha3: Incorrect output from SHAKE squeeze functions
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when attempting to squeeze more than ImpactThis bug impacts users that rely on this XOF API to squeeze more than MitigationStarting from version Fixed in
0.0.8
References Updated Sep 10, 2026 · Source: OSV.dev |
0.0.6-pre.1
unknown
Dependencies (10)
+ 2 more |
|
0.0.5
unknown
3 CVEs
RUSTSEC-2026-0208
May 21, 2026
Potential Panic in AVX2 SHAKE-256
High
Network
Low
None
None
The AVX2-optimized implementation of SHAKE-256 intended for use in ML-KEM and ML-DSA would panic if the length of the output buffers was greater than 32 and not a multiple of 8, due to an out-of-bounds indexing operation. ImpactThis bug impacts users on AVX2 platforms that use the
MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0207
Apr 22, 2026
Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when
attempting to squeeze an output using multiple calls to ImpactThis bug impacts users that rely on this XOF API to squeeze output in
multiple calls where any of the calls request an output length that is
not divisible by MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
GHSA-q29p-9pfr-j652
RUSTSEC-2026-0074
Mar 26, 2026
libcrux-sha3: Incorrect output from SHAKE squeeze functions
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when attempting to squeeze more than ImpactThis bug impacts users that rely on this XOF API to squeeze more than MitigationStarting from version Fixed in
0.0.8
References Updated Sep 10, 2026 · Source: OSV.dev |
0.0.5
unknown
Dependencies (10)
+ 2 more |
|
0.0.5-pre.1
unknown
3 CVEs
RUSTSEC-2026-0208
May 21, 2026
Potential Panic in AVX2 SHAKE-256
High
Network
Low
None
None
The AVX2-optimized implementation of SHAKE-256 intended for use in ML-KEM and ML-DSA would panic if the length of the output buffers was greater than 32 and not a multiple of 8, due to an out-of-bounds indexing operation. ImpactThis bug impacts users on AVX2 platforms that use the
MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0207
Apr 22, 2026
Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when
attempting to squeeze an output using multiple calls to ImpactThis bug impacts users that rely on this XOF API to squeeze output in
multiple calls where any of the calls request an output length that is
not divisible by MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
GHSA-q29p-9pfr-j652
RUSTSEC-2026-0074
Mar 26, 2026
libcrux-sha3: Incorrect output from SHAKE squeeze functions
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when attempting to squeeze more than ImpactThis bug impacts users that rely on this XOF API to squeeze more than MitigationStarting from version Fixed in
0.0.8
References Updated Sep 10, 2026 · Source: OSV.dev |
0.0.5-pre.1
unknown
Dependencies (10)
+ 2 more |
|
0.0.4
unknown
3 CVEs
RUSTSEC-2026-0208
May 21, 2026
Potential Panic in AVX2 SHAKE-256
High
Network
Low
None
None
The AVX2-optimized implementation of SHAKE-256 intended for use in ML-KEM and ML-DSA would panic if the length of the output buffers was greater than 32 and not a multiple of 8, due to an out-of-bounds indexing operation. ImpactThis bug impacts users on AVX2 platforms that use the
MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0207
Apr 22, 2026
Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when
attempting to squeeze an output using multiple calls to ImpactThis bug impacts users that rely on this XOF API to squeeze output in
multiple calls where any of the calls request an output length that is
not divisible by MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
GHSA-q29p-9pfr-j652
RUSTSEC-2026-0074
Mar 26, 2026
libcrux-sha3: Incorrect output from SHAKE squeeze functions
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when attempting to squeeze more than ImpactThis bug impacts users that rely on this XOF API to squeeze more than MitigationStarting from version Fixed in
0.0.8
References Updated Sep 10, 2026 · Source: OSV.dev |
0.0.4
unknown
Dependencies (10)
+ 2 more |
|
0.0.4-pre.1
unknown
3 CVEs
RUSTSEC-2026-0208
May 21, 2026
Potential Panic in AVX2 SHAKE-256
High
Network
Low
None
None
The AVX2-optimized implementation of SHAKE-256 intended for use in ML-KEM and ML-DSA would panic if the length of the output buffers was greater than 32 and not a multiple of 8, due to an out-of-bounds indexing operation. ImpactThis bug impacts users on AVX2 platforms that use the
MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0207
Apr 22, 2026
Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when
attempting to squeeze an output using multiple calls to ImpactThis bug impacts users that rely on this XOF API to squeeze output in
multiple calls where any of the calls request an output length that is
not divisible by MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
GHSA-q29p-9pfr-j652
RUSTSEC-2026-0074
Mar 26, 2026
libcrux-sha3: Incorrect output from SHAKE squeeze functions
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when attempting to squeeze more than ImpactThis bug impacts users that rely on this XOF API to squeeze more than MitigationStarting from version Fixed in
0.0.8
References Updated Sep 10, 2026 · Source: OSV.dev |
0.0.4-pre.1
unknown
Dependencies (10)
+ 2 more |
|
0.0.3
unknown
3 CVEs
RUSTSEC-2026-0208
May 21, 2026
Potential Panic in AVX2 SHAKE-256
High
Network
Low
None
None
The AVX2-optimized implementation of SHAKE-256 intended for use in ML-KEM and ML-DSA would panic if the length of the output buffers was greater than 32 and not a multiple of 8, due to an out-of-bounds indexing operation. ImpactThis bug impacts users on AVX2 platforms that use the
MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0207
Apr 22, 2026
Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when
attempting to squeeze an output using multiple calls to ImpactThis bug impacts users that rely on this XOF API to squeeze output in
multiple calls where any of the calls request an output length that is
not divisible by MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
GHSA-q29p-9pfr-j652
RUSTSEC-2026-0074
Mar 26, 2026
libcrux-sha3: Incorrect output from SHAKE squeeze functions
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when attempting to squeeze more than ImpactThis bug impacts users that rely on this XOF API to squeeze more than MitigationStarting from version Fixed in
0.0.8
References Updated Sep 10, 2026 · Source: OSV.dev |
0.0.3
unknown
Dependencies (8)
|
|
0.0.3-alpha.3
unknown
3 CVEs
RUSTSEC-2026-0208
May 21, 2026
Potential Panic in AVX2 SHAKE-256
High
Network
Low
None
None
The AVX2-optimized implementation of SHAKE-256 intended for use in ML-KEM and ML-DSA would panic if the length of the output buffers was greater than 32 and not a multiple of 8, due to an out-of-bounds indexing operation. ImpactThis bug impacts users on AVX2 platforms that use the
MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0207
Apr 22, 2026
Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when
attempting to squeeze an output using multiple calls to ImpactThis bug impacts users that rely on this XOF API to squeeze output in
multiple calls where any of the calls request an output length that is
not divisible by MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
GHSA-q29p-9pfr-j652
RUSTSEC-2026-0074
Mar 26, 2026
libcrux-sha3: Incorrect output from SHAKE squeeze functions
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when attempting to squeeze more than ImpactThis bug impacts users that rely on this XOF API to squeeze more than MitigationStarting from version Fixed in
0.0.8
References Updated Sep 10, 2026 · Source: OSV.dev |
0.0.3-alpha.3
unknown
Dependencies (8)
|
|
0.0.3-alpha.2
unknown
3 CVEs
RUSTSEC-2026-0208
May 21, 2026
Potential Panic in AVX2 SHAKE-256
High
Network
Low
None
None
The AVX2-optimized implementation of SHAKE-256 intended for use in ML-KEM and ML-DSA would panic if the length of the output buffers was greater than 32 and not a multiple of 8, due to an out-of-bounds indexing operation. ImpactThis bug impacts users on AVX2 platforms that use the
MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0207
Apr 22, 2026
Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when
attempting to squeeze an output using multiple calls to ImpactThis bug impacts users that rely on this XOF API to squeeze output in
multiple calls where any of the calls request an output length that is
not divisible by MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
GHSA-q29p-9pfr-j652
RUSTSEC-2026-0074
Mar 26, 2026
libcrux-sha3: Incorrect output from SHAKE squeeze functions
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when attempting to squeeze more than ImpactThis bug impacts users that rely on this XOF API to squeeze more than MitigationStarting from version Fixed in
0.0.8
References Updated Sep 10, 2026 · Source: OSV.dev |
0.0.3-alpha.2
unknown
Dependencies (8)
|
|
0.0.2
unknown
3 CVEs
RUSTSEC-2026-0208
May 21, 2026
Potential Panic in AVX2 SHAKE-256
High
Network
Low
None
None
The AVX2-optimized implementation of SHAKE-256 intended for use in ML-KEM and ML-DSA would panic if the length of the output buffers was greater than 32 and not a multiple of 8, due to an out-of-bounds indexing operation. ImpactThis bug impacts users on AVX2 platforms that use the
MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0207
Apr 22, 2026
Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when
attempting to squeeze an output using multiple calls to ImpactThis bug impacts users that rely on this XOF API to squeeze output in
multiple calls where any of the calls request an output length that is
not divisible by MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
GHSA-q29p-9pfr-j652
RUSTSEC-2026-0074
Mar 26, 2026
libcrux-sha3: Incorrect output from SHAKE squeeze functions
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when attempting to squeeze more than ImpactThis bug impacts users that rely on this XOF API to squeeze more than MitigationStarting from version Fixed in
0.0.8
References Updated Sep 10, 2026 · Source: OSV.dev |
0.0.2
unknown
Dependencies (8)
|
|
0.0.2-beta.3
unknown
3 CVEs
RUSTSEC-2026-0208
May 21, 2026
Potential Panic in AVX2 SHAKE-256
High
Network
Low
None
None
The AVX2-optimized implementation of SHAKE-256 intended for use in ML-KEM and ML-DSA would panic if the length of the output buffers was greater than 32 and not a multiple of 8, due to an out-of-bounds indexing operation. ImpactThis bug impacts users on AVX2 platforms that use the
MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0207
Apr 22, 2026
Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when
attempting to squeeze an output using multiple calls to ImpactThis bug impacts users that rely on this XOF API to squeeze output in
multiple calls where any of the calls request an output length that is
not divisible by MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
GHSA-q29p-9pfr-j652
RUSTSEC-2026-0074
Mar 26, 2026
libcrux-sha3: Incorrect output from SHAKE squeeze functions
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when attempting to squeeze more than ImpactThis bug impacts users that rely on this XOF API to squeeze more than MitigationStarting from version Fixed in
0.0.8
References Updated Sep 10, 2026 · Source: OSV.dev |
0.0.2-beta.3
unknown
Dependencies (8)
|
|
0.0.2-beta.2
unknown
3 CVEs
RUSTSEC-2026-0208
May 21, 2026
Potential Panic in AVX2 SHAKE-256
High
Network
Low
None
None
The AVX2-optimized implementation of SHAKE-256 intended for use in ML-KEM and ML-DSA would panic if the length of the output buffers was greater than 32 and not a multiple of 8, due to an out-of-bounds indexing operation. ImpactThis bug impacts users on AVX2 platforms that use the
MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0207
Apr 22, 2026
Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when
attempting to squeeze an output using multiple calls to ImpactThis bug impacts users that rely on this XOF API to squeeze output in
multiple calls where any of the calls request an output length that is
not divisible by MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
GHSA-q29p-9pfr-j652
RUSTSEC-2026-0074
Mar 26, 2026
libcrux-sha3: Incorrect output from SHAKE squeeze functions
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when attempting to squeeze more than ImpactThis bug impacts users that rely on this XOF API to squeeze more than MitigationStarting from version Fixed in
0.0.8
References Updated Sep 10, 2026 · Source: OSV.dev |
0.0.2-beta.2
unknown
Dependencies (8)
|
|
0.0.2-alpha.3
unknown
3 CVEs
RUSTSEC-2026-0208
May 21, 2026
Potential Panic in AVX2 SHAKE-256
High
Network
Low
None
None
The AVX2-optimized implementation of SHAKE-256 intended for use in ML-KEM and ML-DSA would panic if the length of the output buffers was greater than 32 and not a multiple of 8, due to an out-of-bounds indexing operation. ImpactThis bug impacts users on AVX2 platforms that use the
MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0207
Apr 22, 2026
Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when
attempting to squeeze an output using multiple calls to ImpactThis bug impacts users that rely on this XOF API to squeeze output in
multiple calls where any of the calls request an output length that is
not divisible by MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
GHSA-q29p-9pfr-j652
RUSTSEC-2026-0074
Mar 26, 2026
libcrux-sha3: Incorrect output from SHAKE squeeze functions
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when attempting to squeeze more than ImpactThis bug impacts users that rely on this XOF API to squeeze more than MitigationStarting from version Fixed in
0.0.8
References Updated Sep 10, 2026 · Source: OSV.dev |
0.0.2-alpha.3
unknown
Dependencies (8)
|
|
0.0.2-alpha.2
unknown
3 CVEs
RUSTSEC-2026-0208
May 21, 2026
Potential Panic in AVX2 SHAKE-256
High
Network
Low
None
None
The AVX2-optimized implementation of SHAKE-256 intended for use in ML-KEM and ML-DSA would panic if the length of the output buffers was greater than 32 and not a multiple of 8, due to an out-of-bounds indexing operation. ImpactThis bug impacts users on AVX2 platforms that use the
MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0207
Apr 22, 2026
Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when
attempting to squeeze an output using multiple calls to ImpactThis bug impacts users that rely on this XOF API to squeeze output in
multiple calls where any of the calls request an output length that is
not divisible by MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
GHSA-q29p-9pfr-j652
RUSTSEC-2026-0074
Mar 26, 2026
libcrux-sha3: Incorrect output from SHAKE squeeze functions
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when attempting to squeeze more than ImpactThis bug impacts users that rely on this XOF API to squeeze more than MitigationStarting from version Fixed in
0.0.8
References Updated Sep 10, 2026 · Source: OSV.dev |
0.0.2-alpha.2
unknown
Dependencies (8)
|
|
0.0.2-alpha.1
unknown
3 CVEs
RUSTSEC-2026-0208
May 21, 2026
Potential Panic in AVX2 SHAKE-256
High
Network
Low
None
None
The AVX2-optimized implementation of SHAKE-256 intended for use in ML-KEM and ML-DSA would panic if the length of the output buffers was greater than 32 and not a multiple of 8, due to an out-of-bounds indexing operation. ImpactThis bug impacts users on AVX2 platforms that use the
MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0207
Apr 22, 2026
Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when
attempting to squeeze an output using multiple calls to ImpactThis bug impacts users that rely on this XOF API to squeeze output in
multiple calls where any of the calls request an output length that is
not divisible by MitigationStarting from version Fixed in
0.0.10
References Updated Jul 17, 2026 · Source: OSV.dev
GHSA-q29p-9pfr-j652
RUSTSEC-2026-0074
Mar 26, 2026
libcrux-sha3: Incorrect output from SHAKE squeeze functions
High
Network
Low
None
None
The incremental squeeze functions in the portable SHAKE XOF API, when attempting to squeeze more than ImpactThis bug impacts users that rely on this XOF API to squeeze more than MitigationStarting from version Fixed in
0.0.8
References Updated Sep 10, 2026 · Source: OSV.dev |
0.0.2-alpha.1
unknown
Dependencies (6)
|