CVE-2025-8556 Details
Description
A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.
A vulnerability exists in CIRCL's implementation of the FourQ elliptic curve, allowing attackers to compromise session security by injecting low-order points and exploiting improper point validation during the Diffie-Hellman key exchange. This flaw could force the identity point, undermining session security.
Users can upgrade to CIRCL version 1.6.1, which addresses the vulnerability by correcting the point validation issues. Instructions for upgrading are available in the CIRCL GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 6, 2025CISA-ADP
Assessed Aug 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://news.ycombinator.com/item?id=45669593 | CVE | |
| https://www.botanica.software/blog/cryptographic-issues-in-cloudflares-circl-fourq-implementation | CVE | |
| https://access.redhat.com/security/cve/CVE-2025-8556 | [email protected] | AdvisoryBundleVendor |
| https://bugzilla.redhat.com/show_bug.cgi?id=2371624 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://github.com/cloudflare/circl | [email protected] | Source CodeVendor |
| https://github.com/cloudflare/circl/security/advisories/GHSA-2x5j-vhc8-9cwm | [email protected] | AdvisoryRemedyVendor |
| https://github.com/cloudflare/circl/tree/v1.6.1 | [email protected] | Source CodeVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1287 | Improper Validation of Specified Type of Input | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Cloudflare CIRCL | < 1.6.1 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 25, 2026 | CVE Modified | [email protected] |
| Oct 22, 2025 | CVE Modified | CVE |
| Aug 6, 2025 | New CVE Received | [email protected] |
Volerion