Skip to content
CloudflareGHSA-2x5j-vhc8-9cwm

CIRCL-Fourq: Missing and wrong validation can lead to incorrect results

LowPublished Jun 10, 2025

### Impact The CIRCL implementation of FourQ fails to validate user-supplied low-order points during Diffie-Hellman key exchange, potentially allowing attackers to force the identity point and compromise session security. Moreover, there is an incorrect point validation in ScalarMult can lead to incorrect results in the isEqual function and if a point is on the curve. ### Patches Version 1.6.1 (https://github.com/cloudflare/circl/tree/v1.6.1) mitigates the identified issues. We acknowledge Alon Livne (Botanica Software Labs) for the reported findings.

GitHub advisory

Affected versions

PackageAffectedFixed in
circl
Product
< 1.6.11.6.1
Details and references

More Cloudflare advisories

All Cloudflare
Advisory
Cloudflare vite plugin exposes secrets over the built-in dev server
LowJul 7, 2025
Request Smuggling Vulnerability in Pingora
High7.4Jun 20, 2025
Incorrect congestion window growth by invalid ACK ranges
High7.5Jun 17, 2025
Incorrect congestion window growth by optimistic ACK
Medium5.3Jun 17, 2025
PKCE bypass via downgrade attack
Medium5.3May 1, 2025
Missing validation of redirect_uri on authorize endpoint
Medium6.0May 1, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.