VendorsOpen Quantum Safeliboqsall versions
Vulnerabilities

Open Quantum Safe liboqs

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2024-31510
An issue in Open Quantum Safe liboqs v.10.0 allows a remote attacker to escalate privileges via the crypto_sign_signature parameter in the /pqcrystals-dilithium-standard_ml-dsa-44-ipd_avx2/sign.c component.
Published 2024-05-24 · Analyzed
9.8EPSS 0.006
CVE-2024-36405
Control-flow timing leak in Kyber reference implementation when compiled with Clang 15-18 for -Os, -O1 and other options
Published 2024-06-10 · Analyzed
7.5EPSS 0.005
CVE-2024-54137
liboqs has a correctness error in HQC decapsulation
Published 2024-12-06 · Analyzed
7.5EPSS 0.004
CVE-2025-52473
liboqs secret-dependent branching in HQC reference implementation when compiled with Clang 17-20
Published 2025-07-10 · Analyzed
5.9EPSS 0.002
CVE-2026-44518
liboqs: XMSS Buffer Overread Bug
Published 2026-05-29 · Analyzed
5.3EPSS 0.004
CVE-2026-46344
liboqs: Heap-buffer-overflow in XMSS verification path via OID-controlled parameter mismatch (xmss_commons.c:194)
Published 2026-05-29 · Analyzed
5.3EPSS 0.004
CVE-2025-48946
liboqs affected by theoretical design flaw in HQC
Published 2025-05-30 · Analyzed
3.7EPSS 0.002