VDB

CVE-2025-52473

CVE-2025-52473 PUBLISHED CVSS 5.900000095367432 MEDIUM

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Multiple secret-dependent branches have been identified in the reference implementation of the HQC key encapsulation mechanism when it is compiled with Clang for optimization levels above -O0 (-O1, -O2, etc). A proof-of-concept local attack exploits this secret-dependent information to recover the entire secret key. This vulnerability is fixed in 0.14.0.

EPSS 0.21% · 10.6th percentile

Risk Scores

CVSS 3.1
5.900000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.21%
10.6th percentile

Affected Products

VendorProductVersions
open-quantum-safeliboqs< 0.14.0
openquantumsafeliboqs0

Timeline

  • Jan 21, 1970 Security Advisory
  • Jul 10, 2025 Coalition ESS Score
  • Jul 10, 2025 CVE Published
  • Jul 10, 2025 CVE Updated
  • Jul 11, 2025 EPSS Score
  • Jul 15, 2025 Coalition ESS Score
  • Jul 20, 2025 EPSS Score
  • Jul 30, 2025 EPSS Score
  • Aug 8, 2025 EPSS Score
  • Aug 18, 2025 EPSS Score
  • Aug 20, 2025 Coalition ESS Score
  • Aug 22, 2025 Coalition ESS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›