CVE-2026-22705Disclosure

LOWCVSS 6.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

RustCrypto: Signatures offers support for digital signatures, which provide authentication of data using public-key cryptography. Prior to version 0.1.0-rc.2, a timing side-channel was discovered in the Decompose algorithm which is used during ML-DSA signing to generate hints for the signature. This issue has been patched in version 0.1.0-rc.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1240

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-02: 1Technical Details · 2026-02-02: 102-02
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Conor Deegan@conordeegan
    Disclosure

    RustCrypto’s ML-DSA advisory is a good example (GHSA-hcp2-x6j4-29j7, CVE-2026-22705), discovered by @trailofbits. It is a timing side-channel caused by a variable-time division occurring on secret-influenced data during signing.

    Post summary

    RustCrypto’s advisory for CVE-2026-22705 discloses a timing side‑channel in ML-DSA caused by variable‑time division during signing.

    210862.5K
    600 followersView on X

Explore more