PT-2025-23341 · Liboqs · Liboqs

Deirdre Connolly

+1

·

Published

2025-05-30

·

Updated

2025-08-25

·

CVE-2025-48946

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions liboqs versions prior to 0.13.0
Description The issue is related to a theoretical design flaw in the HQC algorithm, which is implemented in liboqs. This flaw can lead to large numbers of malformed ciphertexts sharing the same implicit rejection value. Although no concrete attack on the algorithm is currently known, users of HQC must exercise extra caution when using the algorithm in protocols involving key derivation. The HQC algorithm does not provide the same security guarantees as other algorithms like Kyber or ML-KEM.
Recommendations For liboqs versions prior to 0.13.0, consider disabling the HQC algorithm to minimize potential risks until an updated algorithm specification is released by the HQC team and implemented in liboqs. At the moment, there is no information about a newer version that contains a fix for this vulnerability, but HQC is disabled by default in liboqs starting from version 0.13.0.

Exploit

Fix

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

CVE-2025-48946
GHSA-3RXW-4V8Q-9GQ5

Affected Products

Liboqs