Entropy loss and panic via key mishandling
Published Aug 19, 2026 · Updated Aug 20, 2026
Cryptographic flaws in libcrux crates before 0.0.6 and 0.0.7 allow attackers to reduce key entropy or interrupt services. libcrux-ecdh accepted imported X25519 secrets without enforcing length and clamping checks, libcrux-ed25519 clamped the raw 32-byte seed before hashing and then clamped again during scalar derivation, and libcrux-psq panicked on AEAD decryption errors instead of returning AEADError. Exposure depends on applications that let attackers supply X25519 secrets, trigger Ed25519 key generation, or send PSQ ciphertexts; the published scoring bounds the direct consequence to availability loss, while the Ed25519 bug also shrinks the seed space by five bits.
Summary
What happened
Cryptographic flaws in libcrux crates before 0.0.6 and 0.0.7 allow attackers to reduce key entropy or interrupt services. libcrux-ecdh accepted imported X25519 secrets without enforcing length and clamping checks, libcrux-ed25519 clamped the raw 32-byte seed before hashing and then clamped again during scalar derivation, and libcrux-psq panicked on AEAD decryption errors instead of returning AEADError. Exposure depends on applications that let attackers supply X25519 secrets, trigger Ed25519 key generation, or send PSQ ciphertexts; the published scoring bounds the direct consequence to availability loss, while the Ed25519 bug also shrinks the seed space by five bits.
The record
- CVE
- CVE-2026-76234
- Published
- Aug 19, 2026
- Updated
- Aug 20, 2026
- Vendor
- CE Labs
- Product
- libcrux
- Classifications
- CWE-347
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Aug 19, 2026CVE publishedPublication date reported by the CVE source.
- Aug 20, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=0 <0.0.6
- Affected versionversion=0 <0.0.7
What conditions does exploitation require?
What is affected?
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo