CloudflareGHSA-2x5j-vhc8-9cwm
CIRCL-Fourq: Missing and wrong validation can lead to incorrect results
LowPublished Jun 10, 2025
### Impact The CIRCL implementation of FourQ fails to validate user-supplied low-order points during Diffie-Hellman key exchange, potentially allowing attackers to force the identity point and compromise session security. Moreover, there is an incorrect point validation in ScalarMult can lead to incorrect results in the isEqual function and if a point is on the curve. ### Patches Version 1.6.1 (https://github.com/cloudflare/circl/tree/v1.6.1) mitigates the identified issues. We acknowledge Alon Livne (Botanica Software Labs) for the reported findings.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| circl Product | < 1.6.1 | 1.6.1 |
Details and references
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-20
More Cloudflare advisories
All Cloudflare| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 72025 | Cloudflare vite plugin exposes secrets over the built-in dev server | Low | 1.6.0 |
| Jun 202025 | Request Smuggling Vulnerability in Pingora | High7.4 | 0.5.0 |
| Jun 172025 | Incorrect congestion window growth by invalid ACK ranges | High7.5 | 0.24.4 |
| Jun 172025 | Incorrect congestion window growth by optimistic ACK | Medium5.3 | 0.24.4 |
| May 12025 | PKCE bypass via downgrade attack | Medium5.3 | 0.0.5 |
| May 12025 | Missing validation of redirect_uri on authorize endpoint | Medium6.0 | 0.0.5 |