{"id":"GHSA-q29p-9pfr-j652","summary":"libcrux-sha3: Incorrect output from SHAKE squeeze functions","details":"The incremental squeeze functions in the portable SHAKE XOF API, when attempting to squeeze more than `RATE` (168 for SHAKE128, 136 for SHAKE256) bytes, performed an additional permutation of the state before producing the first output block, thus discarding the first block of `RATE` bytes of valid XOF output.\n\n## Impact\nThis bug impacts users that rely on this XOF API to squeeze more than `RATE` bytes. It does not impact the use of libcrux-sha3 in libcrux-ml-kem or libcrux-ml-dsa.\n\n## Mitigation\nStarting from version `0.0.8` the squeeze functions correctly output all blocks including the first block.","aliases":["RUSTSEC-2026-0074"],"modified":"2026-09-10T03:50:40.460818076Z","published":"2026-03-26T17:59:34Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-03-26T17:59:34Z","nvd_published_at":null,"cwe_ids":["CWE-682"]},"references":[{"type":"WEB","url":"https://github.com/cryspen/libcrux/pull/1352"},{"type":"PACKAGE","url":"https://github.com/cryspen/libcrux"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2026-0074.html"}],"affected":[{"package":{"name":"libcrux-sha3","ecosystem":"crates.io","purl":"pkg:cargo/libcrux-sha3"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-q29p-9pfr-j652/GHSA-q29p-9pfr-j652.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}