VDB
CVE-2025-52473
CVE-2025-52473
PUBLISHED
CVSS 5.900000095367432 MEDIUM
liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Multiple secret-dependent branches have been identified in the reference implementation of the HQC key encapsulation mechanism when it is compiled with Clang for optimization levels above -O0 (-O1, -O2, etc). A proof-of-concept local attack exploits this secret-dependent information to recover the entire secret key. This vulnerability is fixed in 0.14.0.
EPSS 0.21% · 10.6th percentile
Risk Scores
CVSS 3.1
5.900000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.21%
10.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| open-quantum-safe | liboqs | < 0.14.0 |
| openquantumsafe | liboqs | 0 |
Timeline
- Jan 21, 1970 Security Advisory
- Jul 10, 2025 Coalition ESS Score
- Jul 10, 2025 CVE Published
- Jul 10, 2025 CVE Updated
- Jul 11, 2025 EPSS Score
- Jul 15, 2025 Coalition ESS Score
- Jul 20, 2025 EPSS Score
- Jul 30, 2025 EPSS Score
- Aug 8, 2025 EPSS Score
- Aug 18, 2025 EPSS Score
- Aug 20, 2025 Coalition ESS Score
- Aug 22, 2025 Coalition ESS Score