Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-21027 | liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Multiple secret-dependent branches have been identified in the reference implementation of the HQC key encapsulation mechanism when it is compiled with Clang for optimization levels above -O0 (-O1, -O2, etc). A proof-of-concept local attack exploits this secret-dependent information to recover the entire secret key. This vulnerability is fixed in 0.14.0. |
Fri, 22 Aug 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openquantumsafe
Openquantumsafe liboqs |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:openquantumsafe:liboqs:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openquantumsafe
Openquantumsafe liboqs |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
Fri, 11 Jul 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-203 | |
| References |
| |
| Metrics |
threat_severity
|
epss
|
Thu, 10 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 10 Jul 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Multiple secret-dependent branches have been identified in the reference implementation of the HQC key encapsulation mechanism when it is compiled with Clang for optimization levels above -O0 (-O1, -O2, etc). A proof-of-concept local attack exploits this secret-dependent information to recover the entire secret key. This vulnerability is fixed in 0.14.0. | |
| Title | liboqs secret-dependent branching in HQC reference implementation when compiled with Clang 17-20 | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-07-10T19:16:29.556Z
Reserved: 2025-06-17T02:28:39.717Z
Link: CVE-2025-52473
Updated: 2025-07-10T19:16:26.673Z
Status : Analyzed
Published: 2025-07-10T19:15:25.387
Modified: 2025-08-22T17:04:49.530
Link: CVE-2025-52473
OpenCVE Enrichment
Updated: 2025-07-12T22:01:21Z
EUVD