CVE-2025-48946 describes a theoretical design flaw in the HQC post-quantum cryptography algorithm, as implemented in liboqs versions prior to 0.13.0. This flaw leads to numerous malformed ciphertexts sharing an implicit rejection value, potentially impacting key derivation protocols. The vulnerability has a low CVSS score of 3.7 (AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N), indicating network access, high attack complexity, and a low impact on confidentiality. Currently, there is no known concrete attack, active exploitation, or publicly available exploit code, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.13.0CPE matchmatch criteria | cpe:2.3:a:openquantumsafe:liboqs:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.