Dalek maintains the curve25519-dalek cryptographic library, a widely used implementation of the Curve25519 elliptic-curve algorithm embedded across multiple Rust projects and applications. Its vulnerability profile centers on compiler-related optimization issues that can inadvertently weaken or remove security-critical code paths, a class of flaw particular to cryptographic libraries where subtle transformations during compilation pose risks to the underlying security guarantees. Current exploitation activity, severity distribution, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dalek over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-58262MEDIUM The curve25519-dalek crate before 4.1.3 for Rust has a constant-time operation on elliptic curve scalars that is removed by LLVM. | Jul 27, 2025 | 5.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dalek.
Media articles that mention a CVE ID that affects a product developed by Dalek — matched by CVE ID, not by vendor name.