CVE-2026-10097
ML-KEM-1024 x64 AVX2 implicit rejection failure in the Fujisaki-Okamoto transform breaks IND-CCA2 security, allowing decapsulation to deviate from the implicit-rejection behavior required by the standard. The AVX2 constant-time ciphertext comparison used during decapsulation never compared the final 32-byte block of the 1568-byte ML-KEM-1024 ciphertext, so a ciphertext manipulated only in those final bytes would compare as equal and decapsulation returned the real shared secret instead of performing the required implicit rejection.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.3
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.26%
- CWE
- CWE-327, CWE-697
- Published
- 2026-06-25
- Last modified
- 2026-06-26
Affected products
- wolfSSL wolfSSL
Weakness type
Related vulnerabilities
- CVE-2026-81822 — AVEVA Pipeline Integrity Monitor Use of a Broken or Risky Cryptographic Algorithm
- CVE-2026-69382 — Microsoft Exchange Server Information Disclosure Vulnerability
- CVE-2026-16693 — IBM i is Affected By Cryptographic Algorithm Weakness in DCM []
- CVE-2026-81859 — Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026.
- CVE-2026-76133 — Ebyte NA111-M Use of a Broken or Risky Cryptographic Algorithm
- CVE-2026-39944 — Ceph: CephX AES Authentication error
- CVE-2025-30156 — Ceph: AES-CBC misuse in CephX and RADOSGW enables authentication bypass and credential forgery
- CVE-2026-77151 — lin-snow Ech0 crypto.go MD5Encrypt risky encryption