GHSA-435g-fcv3-8j26
In accordance with our [security policy for `libcrux`](https://github.com/cryspen/libcrux/blob/main/SECURITY.md), we publish a GitHub security advisory for any releases whose CHANGELOG includes bug-fixes, and encourage our users to upgrade. The latest releases of the `libcrux-ecdh`, `libcrux-ed25519` and `libcrux-psq` crates contain the following bug-fixes: ## `libcrux-ecdh` - [#1301](https://github.com/cryspen/libcrux/pull/1301): Check length and clamping in X25519 secret validation. This is a breaking change since errors are now raised on unclamped X25519 secrets or inputs of the wrong length ## `libcrux-ed25519` - [#1320](https://github.com/cryspen/libcrux/pull/1320): Remove duplicated clamping step during key generation The issue fixed in #1320 was first reported by Nadim Kobeissi. ## `libcrux-psq` - [#1319](https://github.com/cryspen/libcrux/pull/1319): Propagate AEADError instead of panicking - [#1301](https://github.com/cryspen/libcrux/pull/1301): Fix broken clamping check for imported X25519 secret keys The issue fixed in #1319 was first reported by Nadim Kobeissi.
Properties
- ghsa_id
- GHSA-435g-fcv3-8j26
- summary
- Bug-Fixes in `libcrux-ecdh`, `libcrux-ed25519`, `libcrux-psq`
- severity
- low
- cve_id
- GHSA-435g-fcv3-8j26
- is_ghsa_only
- true
- ghsa_published
- 2026-02-12T22:12:14Z
- source_url
- https://github.com/advisories/GHSA-435g-fcv3-8j26
- ghsa_updated
- 2026-02-27T20:51:09Z
Related Entities (6)
AFFECTS (3)
HAS_WEAKNESS (2)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph