sha3
A high-performance native binding to the SHA3 (FIPS 202) cryptographic hashing algorithms, based on the XKCP - eXtended Keccak Code Package. This gem provides support for the standard SHA-3 fixed-length functions (224, 256, 384, and 512 bits), as well as the SHAKE128/SHAKE256 extendable-output functions (XOFs), cSHAKE128/256, and KMAC as specified in NIST SP 800-185.'
Activity
- Latest release
- 3mo ago
- Total releases
- 19
- Cadence
- ~4 months
- Last 12 months
- 1
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Oct 05, 2012
| Version | Released | |
|---|---|---|
2.2.4
patch
| ||
2.2.3
patch
| ||
2.2.2
patch
| ||
2.2.1
patch
| ||
2.2.0
minor
| ||
2.1.0
minor
| ||
2.0.0
major
| ||
1.0.5
patch
| ||
1.0.4
patch
1 CVE
CVE-2022-37454
GHSA-6w4m-2xhg-2658
BIT-libphp-2022-37454
BIT-libpython-2022-37454
BIT-php-2022-37454
BIT-php-min-2022-37454
BIT-python-2022-37454
BIT-python-min-2022-37454
PSF-2022-11
PYSEC-2026-504
Apr 26, 2023
Buffer overflow in sponge queue functions
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThe Keccak sponge function interface accepts partial inputs to be absorbed and partial outputs to be squeezed. A buffer can overflow when partial data with some specific sizes are queued, where at least one of them has a length of 2^32 - 200 bytes or more. PatchesYes, see commit fdc6fef0. WorkaroundsThe problem can be avoided by limiting the size of the partial input data (or partial output digest) below 2^32 - 200 bytes. Multiple calls to the queue system can be chained at a higher level to retain the original functionality. Alternatively, one can process the entire input (or produce the entire output) at once, avoiding the queuing functions altogether. ReferencesSee issue #105 for more details. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.3
0.2.5
0.2.6
1.0.1
1.0.2
1.0.3
1.0.4
Fixed in
1.0.5
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.0.3
patch
1 CVE
CVE-2022-37454
GHSA-6w4m-2xhg-2658
BIT-libphp-2022-37454
BIT-libpython-2022-37454
BIT-php-2022-37454
BIT-php-min-2022-37454
BIT-python-2022-37454
BIT-python-min-2022-37454
PSF-2022-11
PYSEC-2026-504
Apr 26, 2023
Buffer overflow in sponge queue functions
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThe Keccak sponge function interface accepts partial inputs to be absorbed and partial outputs to be squeezed. A buffer can overflow when partial data with some specific sizes are queued, where at least one of them has a length of 2^32 - 200 bytes or more. PatchesYes, see commit fdc6fef0. WorkaroundsThe problem can be avoided by limiting the size of the partial input data (or partial output digest) below 2^32 - 200 bytes. Multiple calls to the queue system can be chained at a higher level to retain the original functionality. Alternatively, one can process the entire input (or produce the entire output) at once, avoiding the queuing functions altogether. ReferencesSee issue #105 for more details. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.3
0.2.5
0.2.6
1.0.1
1.0.2
1.0.3
1.0.4
Fixed in
1.0.5
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.0.2
patch
1 CVE
CVE-2022-37454
GHSA-6w4m-2xhg-2658
BIT-libphp-2022-37454
BIT-libpython-2022-37454
BIT-php-2022-37454
BIT-php-min-2022-37454
BIT-python-2022-37454
BIT-python-min-2022-37454
PSF-2022-11
PYSEC-2026-504
Apr 26, 2023
Buffer overflow in sponge queue functions
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThe Keccak sponge function interface accepts partial inputs to be absorbed and partial outputs to be squeezed. A buffer can overflow when partial data with some specific sizes are queued, where at least one of them has a length of 2^32 - 200 bytes or more. PatchesYes, see commit fdc6fef0. WorkaroundsThe problem can be avoided by limiting the size of the partial input data (or partial output digest) below 2^32 - 200 bytes. Multiple calls to the queue system can be chained at a higher level to retain the original functionality. Alternatively, one can process the entire input (or produce the entire output) at once, avoiding the queuing functions altogether. ReferencesSee issue #105 for more details. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.3
0.2.5
0.2.6
1.0.1
1.0.2
1.0.3
1.0.4
Fixed in
1.0.5
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.0.1
major
1 CVE
CVE-2022-37454
GHSA-6w4m-2xhg-2658
BIT-libphp-2022-37454
BIT-libpython-2022-37454
BIT-php-2022-37454
BIT-php-min-2022-37454
BIT-python-2022-37454
BIT-python-min-2022-37454
PSF-2022-11
PYSEC-2026-504
Apr 26, 2023
Buffer overflow in sponge queue functions
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThe Keccak sponge function interface accepts partial inputs to be absorbed and partial outputs to be squeezed. A buffer can overflow when partial data with some specific sizes are queued, where at least one of them has a length of 2^32 - 200 bytes or more. PatchesYes, see commit fdc6fef0. WorkaroundsThe problem can be avoided by limiting the size of the partial input data (or partial output digest) below 2^32 - 200 bytes. Multiple calls to the queue system can be chained at a higher level to retain the original functionality. Alternatively, one can process the entire input (or produce the entire output) at once, avoiding the queuing functions altogether. ReferencesSee issue #105 for more details. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.3
0.2.5
0.2.6
1.0.1
1.0.2
1.0.3
1.0.4
Fixed in
1.0.5
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.2.6
patch
1 CVE
CVE-2022-37454
GHSA-6w4m-2xhg-2658
BIT-libphp-2022-37454
BIT-libpython-2022-37454
BIT-php-2022-37454
BIT-php-min-2022-37454
BIT-python-2022-37454
BIT-python-min-2022-37454
PSF-2022-11
PYSEC-2026-504
Apr 26, 2023
Buffer overflow in sponge queue functions
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThe Keccak sponge function interface accepts partial inputs to be absorbed and partial outputs to be squeezed. A buffer can overflow when partial data with some specific sizes are queued, where at least one of them has a length of 2^32 - 200 bytes or more. PatchesYes, see commit fdc6fef0. WorkaroundsThe problem can be avoided by limiting the size of the partial input data (or partial output digest) below 2^32 - 200 bytes. Multiple calls to the queue system can be chained at a higher level to retain the original functionality. Alternatively, one can process the entire input (or produce the entire output) at once, avoiding the queuing functions altogether. ReferencesSee issue #105 for more details. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.3
0.2.5
0.2.6
1.0.1
1.0.2
1.0.3
1.0.4
Fixed in
1.0.5
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.2.5
patch
1 CVE
CVE-2022-37454
GHSA-6w4m-2xhg-2658
BIT-libphp-2022-37454
BIT-libpython-2022-37454
BIT-php-2022-37454
BIT-php-min-2022-37454
BIT-python-2022-37454
BIT-python-min-2022-37454
PSF-2022-11
PYSEC-2026-504
Apr 26, 2023
Buffer overflow in sponge queue functions
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThe Keccak sponge function interface accepts partial inputs to be absorbed and partial outputs to be squeezed. A buffer can overflow when partial data with some specific sizes are queued, where at least one of them has a length of 2^32 - 200 bytes or more. PatchesYes, see commit fdc6fef0. WorkaroundsThe problem can be avoided by limiting the size of the partial input data (or partial output digest) below 2^32 - 200 bytes. Multiple calls to the queue system can be chained at a higher level to retain the original functionality. Alternatively, one can process the entire input (or produce the entire output) at once, avoiding the queuing functions altogether. ReferencesSee issue #105 for more details. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.3
0.2.5
0.2.6
1.0.1
1.0.2
1.0.3
1.0.4
Fixed in
1.0.5
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.2.3
patch
1 CVE
CVE-2022-37454
GHSA-6w4m-2xhg-2658
BIT-libphp-2022-37454
BIT-libpython-2022-37454
BIT-php-2022-37454
BIT-php-min-2022-37454
BIT-python-2022-37454
BIT-python-min-2022-37454
PSF-2022-11
PYSEC-2026-504
Apr 26, 2023
Buffer overflow in sponge queue functions
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThe Keccak sponge function interface accepts partial inputs to be absorbed and partial outputs to be squeezed. A buffer can overflow when partial data with some specific sizes are queued, where at least one of them has a length of 2^32 - 200 bytes or more. PatchesYes, see commit fdc6fef0. WorkaroundsThe problem can be avoided by limiting the size of the partial input data (or partial output digest) below 2^32 - 200 bytes. Multiple calls to the queue system can be chained at a higher level to retain the original functionality. Alternatively, one can process the entire input (or produce the entire output) at once, avoiding the queuing functions altogether. ReferencesSee issue #105 for more details. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.3
0.2.5
0.2.6
1.0.1
1.0.2
1.0.3
1.0.4
Fixed in
1.0.5
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.2.2
patch
1 CVE
CVE-2022-37454
GHSA-6w4m-2xhg-2658
BIT-libphp-2022-37454
BIT-libpython-2022-37454
BIT-php-2022-37454
BIT-php-min-2022-37454
BIT-python-2022-37454
BIT-python-min-2022-37454
PSF-2022-11
PYSEC-2026-504
Apr 26, 2023
Buffer overflow in sponge queue functions
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThe Keccak sponge function interface accepts partial inputs to be absorbed and partial outputs to be squeezed. A buffer can overflow when partial data with some specific sizes are queued, where at least one of them has a length of 2^32 - 200 bytes or more. PatchesYes, see commit fdc6fef0. WorkaroundsThe problem can be avoided by limiting the size of the partial input data (or partial output digest) below 2^32 - 200 bytes. Multiple calls to the queue system can be chained at a higher level to retain the original functionality. Alternatively, one can process the entire input (or produce the entire output) at once, avoiding the queuing functions altogether. ReferencesSee issue #105 for more details. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.3
0.2.5
0.2.6
1.0.1
1.0.2
1.0.3
1.0.4
Fixed in
1.0.5
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.2.0
minor
1 CVE
CVE-2022-37454
GHSA-6w4m-2xhg-2658
BIT-libphp-2022-37454
BIT-libpython-2022-37454
BIT-php-2022-37454
BIT-php-min-2022-37454
BIT-python-2022-37454
BIT-python-min-2022-37454
PSF-2022-11
PYSEC-2026-504
Apr 26, 2023
Buffer overflow in sponge queue functions
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThe Keccak sponge function interface accepts partial inputs to be absorbed and partial outputs to be squeezed. A buffer can overflow when partial data with some specific sizes are queued, where at least one of them has a length of 2^32 - 200 bytes or more. PatchesYes, see commit fdc6fef0. WorkaroundsThe problem can be avoided by limiting the size of the partial input data (or partial output digest) below 2^32 - 200 bytes. Multiple calls to the queue system can be chained at a higher level to retain the original functionality. Alternatively, one can process the entire input (or produce the entire output) at once, avoiding the queuing functions altogether. ReferencesSee issue #105 for more details. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.3
0.2.5
0.2.6
1.0.1
1.0.2
1.0.3
1.0.4
Fixed in
1.0.5
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.1.1
patch
1 CVE
CVE-2022-37454
GHSA-6w4m-2xhg-2658
BIT-libphp-2022-37454
BIT-libpython-2022-37454
BIT-php-2022-37454
BIT-php-min-2022-37454
BIT-python-2022-37454
BIT-python-min-2022-37454
PSF-2022-11
PYSEC-2026-504
Apr 26, 2023
Buffer overflow in sponge queue functions
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThe Keccak sponge function interface accepts partial inputs to be absorbed and partial outputs to be squeezed. A buffer can overflow when partial data with some specific sizes are queued, where at least one of them has a length of 2^32 - 200 bytes or more. PatchesYes, see commit fdc6fef0. WorkaroundsThe problem can be avoided by limiting the size of the partial input data (or partial output digest) below 2^32 - 200 bytes. Multiple calls to the queue system can be chained at a higher level to retain the original functionality. Alternatively, one can process the entire input (or produce the entire output) at once, avoiding the queuing functions altogether. ReferencesSee issue #105 for more details. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.3
0.2.5
0.2.6
1.0.1
1.0.2
1.0.3
1.0.4
Fixed in
1.0.5
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.1.0
initial
1 CVE
CVE-2022-37454
GHSA-6w4m-2xhg-2658
BIT-libphp-2022-37454
BIT-libpython-2022-37454
BIT-php-2022-37454
BIT-php-min-2022-37454
BIT-python-2022-37454
BIT-python-min-2022-37454
PSF-2022-11
PYSEC-2026-504
Apr 26, 2023
Buffer overflow in sponge queue functions
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThe Keccak sponge function interface accepts partial inputs to be absorbed and partial outputs to be squeezed. A buffer can overflow when partial data with some specific sizes are queued, where at least one of them has a length of 2^32 - 200 bytes or more. PatchesYes, see commit fdc6fef0. WorkaroundsThe problem can be avoided by limiting the size of the partial input data (or partial output digest) below 2^32 - 200 bytes. Multiple calls to the queue system can be chained at a higher level to retain the original functionality. Alternatively, one can process the entire input (or produce the entire output) at once, avoiding the queuing functions altogether. ReferencesSee issue #105 for more details. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.3
0.2.5
0.2.6
1.0.1
1.0.2
1.0.3
1.0.4
Fixed in
1.0.5
References
Updated Sep 10, 2026 · Source: OSV.dev |