libcrux-sha3 is vulnerable to Incorrect Calculation
82
High Risk
A flaw in the portable SHAKE XOF incremental squeeze implementation could produce incorrect output when the output is retrieved across multiple squeeze calls with lengths that are not divisible by the algorithm's rate. Due to improper buffering of partially consumed output blocks, bytes could be dropped, resulting in incorrect cryptographic output and potentially compromising applications that rely on the API for incremental SHAKE operations.
You are affected if you are using a version that falls within the vulnerable range and you are using the libcrux_sha3::portable::incremental::Shake128Xof::squeeze or libcrux_sha3::portable::incremental::Shake256Xof::squeeze functions.
libcrux-sha3 is vulnerable to Incorrect Calculation in versions 0.0.0 - 0.0.9.
Upgrade the libcrux-sha3 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant