highVulnerability

GHSA-pv9v-5j35-xwcr

An incorrect constant for the key length in libcrux-poly1305 caused the standalone MAC function `libcrux_poly1305::mac` to always panic with an out-of-bounds memory access. ## Impact Applications wishing to use libcrux-poly1305 as a standalone MAC would experience panics. The use of libcrux-poly1305 in libcrux-chacha20poly1305 is unaffected. ## Mitigation Starting from version `0.0.5`, the correct value is used for the key length constant.

Properties

ghsa_id
GHSA-pv9v-5j35-xwcr
severity
high
summary
libcrux Panics During Standalone MAC Operations
cve_id
GHSA-pv9v-5j35-xwcr
is_ghsa_only
true
ghsa_published
2026-03-26T18:00:05Z
source_url
https://github.com/advisories/GHSA-pv9v-5j35-xwcr
ghsa_updated
2026-03-26T18:00:06Z

Related Entities (4)

AFFECTS (1)

[Software]rust/libcrux-poly1305

HAS_WEAKNESS (2)

[Weakness]Buffer Access with Incorrect Length Value
[Weakness]Out-of-bounds Read

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-pv9v-5j35-xwcr — Ninja Signal Threat Intelligence | Ninja Signal