Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Zhiyuan Zhang

#39374of 53,633
6.9Total CVSS
Vulnerabilities · 2
Low
1
Medium
1
PT-2025-50637
1.0
2025-12-11
Wolfssl · Wolfssl · CVE-2025-13912
**Name of the Vulnerable Software and Affected Versions** wolfSSL versions prior to 5.8.4 **Description** Certain constant-time implementations within wolfSSL may be altered by LLVM optimizations into non-constant-time binaries. This transformation can introduce observable timing discrepancies, potentially leading to information disclosure through timing side-channel attacks. **Recommendations** Update to wolfSSL version 5.8.4 or later.
PT-2025-29131
5.9
2025-07-10
Liboqs · Liboqs · CVE-2025-52473
Name of the Vulnerable Software and Affected Versions: liboqs versions prior to 0.14.0 Description: liboqs is a C-language cryptographic library providing post-quantum cryptography algorithm implementations. Secret-dependent branches were identified in the HQC key encapsulation mechanism reference implementation when compiled with Clang at optimization levels above -O0. A proof-of-concept local attack exploits this secret-dependent information to recover the entire secret key. Recommendations: Update to version 0.14.0 or later.