CVE-2026-46654

Plonky3 is a toolkit for polynomial IOPs (PIOPs). Prior to versions 0.4.3 and 0.5.3, an attacker controlling prover-side observations can craft distinct transcripts that produce identical challenges, breaking the binding property of Fiat-Shamir. This issue has been patched in versions 0.4.3 and 0.5.3.

Scoring

Severity
HIGH
CVSS base score
8.9
CVSS vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
EPSS probability
0.11%
CWE
CWE-1240, CWE-345
Published
2026-06-10
Last modified
2026-06-11

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs