mediumVulnerability

GHSA-g433-pq76-6cmf

We publish a GitHub security advisory for any releases whose CHANGELOG includes bug-fixes, and encourage our users to upgrade. The latest releases of the hpke-rs and hpke-rs-rust-crypto crates contain the following bug-fixes: ## hpke-rs - [#127](https://github.com/cryspen/hpke-rs/pull/127): Fix `KemAlgorithm::TryFrom<u16>` mapping where `0x004D` incorrectly resolved to `XWingDraft06` instead of `XWingDraft06Obsolete`. - [#123](https://github.com/cryspen/hpke-rs/pull/123): Fix potential overflow in context counter and switch to use u64. - [#128](https://github.com/cryspen/hpke-rs/pull/128): Return errors when trying to use open/seal with export only ciphersuite and when using kdf export with an output that's too long (instead of truncating it) The issue fixed in #123 was first reported by Nadim Kobeissi. The issues fixed in #127 and #128 were first reported by Scott Arciszewski. ## hpke-rs-rust-crypto - [#124](https://github.com/cryspen/hpke-rs/pull/124): Error out on x25519 0 keys The issue fixed in #124 was first reported by Nadim Kobeissi.

Properties

ghsa_id
GHSA-g433-pq76-6cmf
severity
medium
summary
Bug fixes in hpke-rs, hpke-rs-rust-crypto
cve_id
GHSA-g433-pq76-6cmf
is_ghsa_only
true
ghsa_published
2026-02-13T20:05:10Z
source_url
https://github.com/advisories/GHSA-g433-pq76-6cmf
ghsa_updated
2026-02-13T20:05:11Z

Related Entities (6)

AFFECTS (2)

[Software]rust/hpke-rs-rust-crypto
[Software]rust/hpke-rs

HAS_WEAKNESS (3)

[Weakness]Improper Input Validation
[Weakness]Integer Overflow or Wraparound
[Weakness]Incorrect Comparison

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-g433-pq76-6cmf — Ninja Signal Threat Intelligence | Ninja Signal