Openquantumsafe
Openquantumsafe Liboqs: vulnerabilidades y CVE
Openquantumsafe Liboqs tiene 8 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses2
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-46344 | Media (5.3) | 0.30% | — | 29 may 2026 | liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS and XMSS^MT stateful signature… |
| CVE-2026-44518 | Media (5.3) | 0.30% | — | 29 may 2026 | liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS and XMSS^MT stateful signature… |
| CVE-2025-52473 | Media (5.5) | 0.22% | — | 10 jul 2025 | liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Multiple secret-dependent branches have been identified in the reference implementation of the HQC key… |
| CVE-2025-48946 | Baja (3.7) | 0.24% | — | 30 may 2025 | liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. liboqs prior to version 0.13.0 supports the HQC algorithm, an algorithm with a theoretical design flaw… |
| CVE-2024-54137 | Alta (7.5) | 0.40% | — | 6 dic 2024 | liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A correctness error has been identified in the reference implementation of the HQC key encapsulation… |
| CVE-2024-37305 | Alta (8.2) | 0.45% | — | 17 jun 2024 | oqs-provider is a provider for the OpenSSL 3 cryptography library that adds support for post-quantum cryptography in TLS, X.509, and S/MIME using post-quantum algorithms from liboqs. Flaws have been identified in the… |
| CVE-2024-36405 | Alta (7.5) | 0.52% | — | 10 jun 2024 | liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A control-flow timing lean has been identified in the reference implementation of the Kyber key… |
| CVE-2024-31510 | Crítica (9.8) | 0.62% | — | 24 may 2024 | An issue in Open Quantum Safe liboqs v.10.0 allows a remote attacker to escalate privileges via the crypto_sign_signature parameter in the /pqcrystals-dilithium-standard_ml-dsa-44-ipd_avx2/sign.c component. |