Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hcp2-x6j4-29j7 | RustCrypto: Signatures has timing side-channel in ML-DSA decomposition |
Mon, 12 Jan 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 12 Jan 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rustcrypto
Rustcrypto signatures |
|
| Vendors & Products |
Rustcrypto
Rustcrypto signatures |
Sat, 10 Jan 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | RustCrypto: Signatures offers support for digital signatures, which provide authentication of data using public-key cryptography. Prior to version 0.1.0-rc.2, a timing side-channel was discovered in the Decompose algorithm which is used during ML-DSA signing to generate hints for the signature. This issue has been patched in version 0.1.0-rc.2. | |
| Title | RustCrypto: Signatures has timing side-channel in ML-DSA decomposition | |
| Weaknesses | CWE-1240 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-12T16:43:06.463Z
Reserved: 2026-01-08T19:23:09.857Z
Link: CVE-2026-22705
Updated: 2026-01-12T16:43:01.889Z
Status : Deferred
Published: 2026-01-10T07:16:03.363
Modified: 2026-04-15T00:35:42.020
Link: CVE-2026-22705
No data.
OpenCVE Enrichment
Updated: 2026-04-18T07:15:25Z
Github GHSA