{"id":"GHSA-435g-fcv3-8j26","summary":"Bug-Fixes in `libcrux-ecdh`, `libcrux-ed25519`, `libcrux-psq`","details":"In accordance with our [security policy for `libcrux`](https://github.com/cryspen/libcrux/blob/main/SECURITY.md), we publish a GitHub security advisory for any releases whose CHANGELOG includes bug-fixes, and encourage our users to upgrade. The latest releases of the `libcrux-ecdh`, `libcrux-ed25519` and `libcrux-psq` crates contain the following bug-fixes:\n\n## `libcrux-ecdh`\n\n- [#1301](https://github.com/cryspen/libcrux/pull/1301): Check length and clamping in X25519 secret validation. This is a breaking change since errors are now raised on unclamped X25519 secrets or inputs of the wrong length\n\n## `libcrux-ed25519`\n\n- [#1320](https://github.com/cryspen/libcrux/pull/1320): Remove duplicated clamping step during key generation\n\nThe issue fixed in #1320 was first reported by Nadim Kobeissi.\n## `libcrux-psq`\n\n- [#1319](https://github.com/cryspen/libcrux/pull/1319): Propagate AEADError instead of panicking\n- [#1301](https://github.com/cryspen/libcrux/pull/1301): Fix broken clamping check for imported X25519 secret keys\n\nThe issue fixed in #1319 was first reported by Nadim Kobeissi.","aliases":["CVE-2026-76234","RUSTSEC-2026-0023","RUSTSEC-2026-0024","RUSTSEC-2026-0025","RUSTSEC-2026-0026"],"modified":"2026-08-20T04:03:48.330165805Z","published":"2026-02-12T22:12:14Z","database_specific":{"cwe_ids":["CWE-20","CWE-327"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2026-02-12T22:12:14Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/cryspen/libcrux/security/advisories/GHSA-435g-fcv3-8j26"},{"type":"WEB","url":"https://github.com/cryspen/libcrux/pull/1301"},{"type":"WEB","url":"https://github.com/cryspen/libcrux/pull/1319"},{"type":"WEB","url":"https://github.com/cryspen/libcrux/pull/1320"},{"type":"WEB","url":"https://github.com/cryspen/libcrux/commit/4d6f5d3c2542b6179a6474dec8cfb8b8ddf31a84"},{"type":"WEB","url":"https://github.com/cryspen/libcrux/commit/a09022c5811ca7fd1c6d9a239ff294d64ee86734"},{"type":"WEB","url":"https://github.com/cryspen/libcrux/commit/f303b6446c19fe9a7c993f61e426023609cd5fac"},{"type":"PACKAGE","url":"https://github.com/cryspen/libcrux"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2026-0023.html"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2026-0024.html"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2026-0025.html"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2026-0026.html"}],"affected":[{"package":{"name":"libcrux-ecdh","ecosystem":"crates.io","purl":"pkg:cargo/libcrux-ecdh"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.6"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.0.5","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-435g-fcv3-8j26/GHSA-435g-fcv3-8j26.json"}},{"package":{"name":"libcrux-ed25519","ecosystem":"crates.io","purl":"pkg:cargo/libcrux-ed25519"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.6"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.0.5","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-435g-fcv3-8j26/GHSA-435g-fcv3-8j26.json"}},{"package":{"name":"libcrux-psq","ecosystem":"crates.io","purl":"pkg:cargo/libcrux-psq"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-435g-fcv3-8j26/GHSA-435g-fcv3-8j26.json","last_known_affected_version_range":"\u003c= 0.0.6"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N"}]}