openquantumsafe records
7 published records for vendor openquantumsafe.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 71.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm2
- CWE-125 Out-of-bounds Read1
- CWE-20 Improper Input Validation1
- CWE-208 Observable Timing Discrepancy1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-31510No exploit | An issue in Open Quantum Safe liboqs v.10.0 allows a remote attacker to escalate privileges via the crypto_sign_signature parameter in the /openquantumsafe · liboqs · CWE-327 | Critical9.8 | — | 0.6% | May 24, 2024 |
30Monitor | CVE-2024-36405No exploit | Control-flow timing leak in Kyber reference implementation when compiled with Clang 15-18 for -Os, -O1 and other optionsopenquantumsafe · liboqs · CWE-208 | High7.5 | — | 0.5% | Jun 10, 2024 |
30Monitor | CVE-2024-54137No exploit | liboqs has a correctness error in HQC decapsulationopenquantumsafe · liboqs · CWE-200 | High7.5 | — | 0.4% | Dec 6, 2024 |
22Monitor | CVE-2025-52473No exploit | liboqs secret-dependent branching in HQC reference implementation when compiled with Clang 17-20openquantumsafe · liboqs · CWE-200 | Medium5.5 | — | 0.2% | Jul 10, 2025 |
21Monitor | CVE-2026-46344No exploit | liboqs: Heap-buffer-overflow in XMSS verification path via OID-controlled parameter mismatch (xmss_commons.c:194)openquantumsafe · liboqs · CWE-125 | Medium5.3 | — | 0.3% | May 29, 2026 |
21Monitor | CVE-2026-44518No exploit | liboqs: XMSS Buffer Overread Bugopenquantumsafe · liboqs · CWE-20 | Medium5.3 | — | 0.3% | May 29, 2026 |
14Monitor | CVE-2025-48946No exploit | liboqs affected by theoretical design flaw in HQCopenquantumsafe · liboqs · CWE-327 | Low3.7 | — | 0.2% | May 30, 2025 |
- CVE-2024-3151039Monitor
An issue in Open Quantum Safe liboqs v.10.0 allows a remote attacker to escalate privileges via the crypto_sign_signature parameter in the /
CriticalCVSS 9.8No exploitEPSS 1%openquantumsafe · liboqsMay 24, 2024
- CVE-2024-3640530Monitor
Control-flow timing leak in Kyber reference implementation when compiled with Clang 15-18 for -Os, -O1 and other options
HighCVSS 7.5No exploitEPSS 1%openquantumsafe · liboqsJun 10, 2024
- CVE-2024-5413730Monitor
liboqs has a correctness error in HQC decapsulation
HighCVSS 7.5No exploitEPSS 0%openquantumsafe · liboqsDec 6, 2024
- CVE-2025-5247322Monitor
liboqs secret-dependent branching in HQC reference implementation when compiled with Clang 17-20
MediumCVSS 5.5No exploitEPSS 0%openquantumsafe · liboqsJul 10, 2025
- CVE-2026-4634421Monitor
liboqs: Heap-buffer-overflow in XMSS verification path via OID-controlled parameter mismatch (xmss_commons.c:194)
MediumCVSS 5.3No exploitEPSS 0%openquantumsafe · liboqsMay 29, 2026
- CVE-2026-4451821Monitor
liboqs: XMSS Buffer Overread Bug
MediumCVSS 5.3No exploitEPSS 0%openquantumsafe · liboqsMay 29, 2026
- CVE-2025-4894614Monitor
liboqs affected by theoretical design flaw in HQC
LowCVSS 3.7No exploitEPSS 0%openquantumsafe · liboqsMay 30, 2025