ml-dsa
crates.io2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting ml-dsapage 1 of 1
- CVE-2026-22705MEDIUMCVSS 6.4EG 6.4✓ Fixed in 0.1.0-rc.32026-01-10
RustCrypto: Signatures offers support for digital signatures, which provide authentication of data using public-key cryptography. Prior to version 0.1.0-rc.2, a timing side-channel was discovered in the Decompose algorithm which is used du…
- CVE-2026-24850MEDIUMCVSS 5.3EG 5.3✓ Fixed in 0.1.0-rc.42026-01-28
The ML-DSA crate is a Rust implementation of the Module-Lattice-Based Digital Signature Standard (ML-DSA). Starting in version 0.0.4 and prior to version 0.1.0-rc.4, the ML-DSA signature verification implementation in the RustCrypto `ml-ds…
Check whether ml-dsa is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for ml-dsa CVEs against the assets you own.
Start Free Scan →