CVE-2025-8556

A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.
Configurations

No configuration.

History

22 Oct 2025, 21:15

Type Values Removed Values Added
References
  • () https://news.ycombinator.com/item?id=45669593 -
  • () https://www.botanica.software/blog/cryptographic-issues-in-cloudflares-circl-fourq-implementation -

06 Aug 2025, 20:23

Type Values Removed Values Added
Summary
  • (es) Se detectó una falla en la implementación de la curva elíptica FourQ de CIRCL. Esta vulnerabilidad permite a un atacante comprometer la seguridad de la sesión mediante la inyección de puntos de orden inferior y una validación incorrecta de puntos durante el intercambio de claves Diffie-Hellman.

06 Aug 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-06 09:15

Updated : 2025-10-22 21:15


NVD link : CVE-2025-8556

Mitre link : CVE-2025-8556

CVE.ORG link : CVE-2025-8556


JSON object : View

Products Affected

No product.

CWE
CWE-347

Improper Verification of Cryptographic Signature