Vulnerability RUSTSEC-2026-0330

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
8 days ago
September 28, 2026 at 12:00 PM UTC
Hybrid Encapsulation from Seed Panics on Short Seed
0.0.2 and 0.0.3 and 0.0.4 and 0.0.5 and 0.0.6 and 0.0.7 and 0.0.8 and 0.0.9
0.0.2 and 0.0.3 and 0.0.4 and 0.0.5 and 0.0.6 and 0.0.7 and 0.0.8 and 0.0.9

Summary

Hybrid Encapsulation from Seed Panics on Short Seed

Details

For a hybrid KEM public key of type PublicKey::WingKemDraft06 or PublicKey::X25519MlKem768Draft06, the PublicKey::encapsulate_derand function would panic in an indexing operation on a seed input of length shorter than 32 bytes.

Impact

Applications encapsulating with an attacker controlled seed value could be made to panic. Since the encapsulation seed should be considered a secret of the encapsulating party for the KEM to remain secure, an application should never take the seed value from a potentially attacker controlled source.

Mitigation

With release of version 0.0.10 of libcrux-kem this bug has been fixed and the serialization functions return InvalidPrivateKey and InvalidPublicKey errors on invalid input buffer lengths.

We recommend users upgrade to libcrux-kem version 0.0.10.

Impacted packages

Timeline

Published
8 days ago
September 28, 2026 at 12:00 PM UTC
Fixed (0.0.10)
3 hours ago
October 07, 2026 at 06:33 AM UTC
Last Modified
1 hour ago
October 07, 2026 at 08:30 AM UTC