Advisory Database
  • Advisories
  • Dependency Scanning
  1. cargo
  2. ›
  3. hpke-rs-rust-crypto
  4. ›
  5. GHSA-g433-pq76-6cmf

GHSA-g433-pq76-6cmf: Bug fixes in hpke-rs, hpke-rs-rust-crypto

February 13, 2026

We publish a GitHub security advisory for any releases whose CHANGELOG includes bug-fixes, and encourage our users to upgrade. The latest releases of the hpke-rs and hpke-rs-rust-crypto crates contain the following bug-fixes:

References

  • github.com/advisories/GHSA-g433-pq76-6cmf
  • github.com/cryspen/hpke-rs
  • github.com/cryspen/hpke-rs/commit/1c247b5c9aeca602ad2971c9bd49817fe2c308e6
  • github.com/cryspen/hpke-rs/commit/25248bd624cc0325c98a05c169a0c9aa0aced632
  • github.com/cryspen/hpke-rs/commit/3a8254938f43bdc4e0c9c4f987f8071f19779066
  • github.com/cryspen/hpke-rs/commit/b54c8bb83906331bdf4f606cafa30cd7fd20b531
  • github.com/cryspen/hpke-rs/pull/123
  • github.com/cryspen/hpke-rs/pull/124
  • github.com/cryspen/hpke-rs/pull/127
  • github.com/cryspen/hpke-rs/pull/128
  • github.com/cryspen/hpke-rs/security/advisories/GHSA-g433-pq76-6cmf

Code Behaviors & Features

Detect and mitigate GHSA-g433-pq76-6cmf with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 0.6.0

Fixed versions

  • 0.6.0

Solution

Upgrade to version 0.6.0 or above.

Weakness

  • CWE-190: Integer Overflow or Wraparound
  • CWE-20: Improper Input Validation
  • CWE-697: Incorrect Comparison

Source file

cargo/hpke-rs-rust-crypto/GHSA-g433-pq76-6cmf.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 25 Mar 2026 00:19:11 +0000.