Open Quantum Safe maintains liboqs, a narrowly scoped but strategically important cryptographic library that integrates post-quantum algorithm implementations into applications across research, infrastructure, and emerging quantum-safe deployment efforts. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur through weakness classes including sensitive-information exposure, out-of-bounds reads, timing-channel side channels, and cryptographic algorithm weaknesses that reflect the complexity of novel post-quantum primitives and their constant-time implementation demands. Defenders tracking quantum-safe migration should inventory products that depend on liboqs and treat this library's security advisories as high-priority given the cryptographic trust boundary it occupies; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openquantumsafe over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-31510CRITICAL An issue in Open Quantum Safe liboqs v.10.0 allows a remote attacker to escalate privileges via the crypto_sign_signature parameter in the /pqcrystals-dilithium-standard_ml-dsa-44- | May 24, 2024 | 9.8 | 30 | NO | NO |
CVE-2026-46344MEDIUM liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in th | May 29, 2026 | 5.3 | 25 | NO | NO |
CVE-2026-44518MEDIUM liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in th | May 29, 2026 | 5.3 | 25 | NO | NO |
CVE-2024-36405HIGH liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A control-flow timing lean has been identified in the reference | Jun 10, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-54137HIGH liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A correctness error has been identified in the reference impleme | Dec 6, 2024 | 7.5 | 21 | NO | NO |
CVE-2025-52473MEDIUM liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Multiple secret-dependent branches have been identified in the r | Jul 10, 2025 | 5.5 | 17 | NO | NO |
liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. liboqs prior to version 0.13.0 supports the HQC algorithm, an al | May 30, 2025 | 3.7 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openquantumsafe.
Media articles that mention a CVE ID that affects a product developed by Openquantumsafe — matched by CVE ID, not by vendor name.