{"id":"GHSA-g433-pq76-6cmf","aliases":["RUSTSEC-2026-0069","RUSTSEC-2026-0070","RUSTSEC-2026-0071","RUSTSEC-2026-0072"],"url":"https://o3.security/vulnerability/GHSA-g433-pq76-6cmf","summary":"Bug fixes in hpke-rs, hpke-rs-rust-crypto","details":"We publish a GitHub security advisory for any releases whose CHANGELOG includes bug-fixes, and encourage our users to upgrade. The latest releases of the hpke-rs and hpke-rs-rust-crypto crates contain the following bug-fixes:\n\n## hpke-rs\n- [#127](https://github.com/cryspen/hpke-rs/pull/127): Fix `KemAlgorithm::TryFrom<u16>` mapping where `0x004D` incorrectly resolved to `XWingDraft06` instead of `XWingDraft06Obsolete`.\n- [#123](https://github.com/cryspen/hpke-rs/pull/123): Fix potential overflow in context counter and switch to use u64.\n- [#128](https://github.com/cryspen/hpke-rs/pull/128): Return errors when trying to use open/seal with export only ciphersuite and when using kdf export with an output that's too long (instead of truncating it)\n\nThe issue fixed in #123 was first reported by Nadim Kobeissi.\nThe issues fixed in #127 and #128 were first reported by Scott Arciszewski.\n\n## hpke-rs-rust-crypto\n- [#124](https://github.com/cryspen/hpke-rs/pull/124): Error out on x25519 0 keys\n\nThe issue fixed in #124 was first reported by Nadim Kobeissi.","published":"2026-02-13T20:05:10Z","modified":"2026-03-25T21:48:54.711298Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"hpke-rs","fixedVersion":"0.6.0"},{"ecosystem":"crates.io","name":"hpke-rs-rust-crypto","fixedVersion":"0.6.0"}],"fix":{"url":"https://github.com/cryspen/hpke-rs/pull/123","label":"cryspen/hpke-rs#123"},"references":[{"type":"WEB","url":"https://github.com/cryspen/hpke-rs/security/advisories/GHSA-g433-pq76-6cmf"},{"type":"WEB","url":"https://github.com/cryspen/hpke-rs/pull/123"},{"type":"WEB","url":"https://github.com/cryspen/hpke-rs/pull/124"},{"type":"WEB","url":"https://github.com/cryspen/hpke-rs/pull/127"},{"type":"WEB","url":"https://github.com/cryspen/hpke-rs/pull/128"},{"type":"WEB","url":"https://github.com/cryspen/hpke-rs/commit/1c247b5c9aeca602ad2971c9bd49817fe2c308e6"},{"type":"WEB","url":"https://github.com/cryspen/hpke-rs/commit/25248bd624cc0325c98a05c169a0c9aa0aced632"},{"type":"WEB","url":"https://github.com/cryspen/hpke-rs/commit/3a8254938f43bdc4e0c9c4f987f8071f19779066"},{"type":"WEB","url":"https://github.com/cryspen/hpke-rs/commit/b54c8bb83906331bdf4f606cafa30cd7fd20b531"},{"type":"PACKAGE","url":"https://github.com/cryspen/hpke-rs"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2026-0070.html"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2026-0072.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-03-25T21:48:54.711298Z"}}