
Cloud Vulnerability DB
A community-led vulnerabilities database
Computing an X25519 shared secret with
x25519_dalek::StaticSecret::diffie_hellman does not include the
check that the key exchange was contributory, i.e. does not ensure on
its own that the resulting shared secret is non-zero.
RFC 9180 mandates that implementations of HPKE must check for all zero Diffie-Hellman shared secrets and abort if so. Applications using hpke-rs with the RustCryto provider would not perform this check allowing for non-contributive Diffie-Hellman shared secrets. Applications using hpke-rs with the libcrux provider are not affected.
Starting with version 0.6.0, an error will be returned when
the computed Diffie-Hellman shared secret is all-zero.
Source: NVD
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."