lowVulnerability

GHSA-435g-fcv3-8j26

In accordance with our [security policy for `libcrux`](https://github.com/cryspen/libcrux/blob/main/SECURITY.md), we publish a GitHub security advisory for any releases whose CHANGELOG includes bug-fixes, and encourage our users to upgrade. The latest releases of the `libcrux-ecdh`, `libcrux-ed25519` and `libcrux-psq` crates contain the following bug-fixes: ## `libcrux-ecdh` - [#1301](https://github.com/cryspen/libcrux/pull/1301): Check length and clamping in X25519 secret validation. This is a breaking change since errors are now raised on unclamped X25519 secrets or inputs of the wrong length ## `libcrux-ed25519` - [#1320](https://github.com/cryspen/libcrux/pull/1320): Remove duplicated clamping step during key generation The issue fixed in #1320 was first reported by Nadim Kobeissi. ## `libcrux-psq` - [#1319](https://github.com/cryspen/libcrux/pull/1319): Propagate AEADError instead of panicking - [#1301](https://github.com/cryspen/libcrux/pull/1301): Fix broken clamping check for imported X25519 secret keys The issue fixed in #1319 was first reported by Nadim Kobeissi.

Properties

ghsa_id
GHSA-435g-fcv3-8j26
summary
Bug-Fixes in `libcrux-ecdh`, `libcrux-ed25519`, `libcrux-psq`
severity
low
cve_id
GHSA-435g-fcv3-8j26
is_ghsa_only
true
ghsa_published
2026-02-12T22:12:14Z
source_url
https://github.com/advisories/GHSA-435g-fcv3-8j26
ghsa_updated
2026-02-27T20:51:09Z

Related Entities (6)

AFFECTS (3)

[Software]rust/libcrux-ed25519
[Software]rust/libcrux-psq
[Software]rust/libcrux-ecdh

HAS_WEAKNESS (2)

[Weakness]Improper Input Validation
[Weakness]Use of a Broken or Risky Cryptographic Algorithm

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph