CVE-2026-24850Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The ML-DSA crate is a Rust implementation of the Module-Lattice-Based Digital Signature Standard (ML-DSA). Starting in version 0.0.4 and prior to version 0.1.0-rc.4, the ML-DSA signature verification implementation in the RustCrypto `ml-dsa` crate incorrectly accepts signatures with repeated (duplicate) hint indices. According to the ML-DSA specification (FIPS 204 / RFC 9881), hint indices within each polynomial must be **strictly increasing**. The current implementation uses a non-strict monotonic check (`<=` instead of `<`), allowing duplicate indices. This is a regression bug. The original implementation was correct, but a commit in version 0.0.4 inadvertently changed the strict `<` comparison to `<=`, introducing the vulnerability. Version 0.1.0-rc.4 fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-01-28); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-01-28: 3Mentions · 2026-09-23: 1Patch / Workaround · 2026-09-23: 1Technical Details · 2026-01-28: 201-2809-23
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-283
Disclosure3
2026-09-231
Patch1
Full discourse4 posts
  • Rafael@Corvo_Arkhen
    Patch

    A criptografia usa ML-DSA-65 (CRYSTALS-Dilithium), o padrão NIST FIPS 204: • Chave pública: 1952 bytes • Assinatura: 3309 bytes O crate fixa ml-dsa = "0.1.1", que corrige quatro advisories conhecidas (RUSTSEC-2025-0144, CVE-2026-24850, GHSA-h37v-hp6w-2pp8). ⚠️ Requer Rust ≥ 1.85.0 (edition2024).

    Post summary

    The text announces that ml-dsa crate version 0.1.1 fixes four known advisories including CVE-2026-24850, serving as a patch announcement.

    1000032
    738 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-24850: Mall-DSA: Breaking Post-Quantum Promises with a Single Typo A subtle logic error in the Rust `ml-dsa` crate implementation of the Module-Lattice-Based Digital Signature Standard (ML-DSA) allowed for signature malleability. By relaxing ... https://cvereports.com/reports/CVE-2026-24850

    Post summary

    The report outlines a logic error in the Rust ml-dsa crate that enables signature malleability, but offers no PoC, exploit, or patch information.

    0000021
    29 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24850 Signature Verification Bypass in RustCrypto ML-DSA Crate Before 0.1.0-rc.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24850

    Post summary

    A new vulnerability, CVE-2026-24850, has been identified as a signature verification bypass in the RustCrypto ML-DSA crate (versions prior to 0.1.0-rc.4); no PoC, exploit, or mitigation details are provided in the text.

    0000072
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24850 The ML-DSA crate is a Rust implementation of the Module-Lattice-Based Digital Signature Standard (ML-DSA). Starting in version 0.0.4 and prior to version 0.1.0-rc.4, … https://www.cve.org/CVERecord?id=CVE-2026-24850

    Post summary

    The post announces a vulnerability in the Rust-based ML‑DSA crate, listing affected versions but providing no further technical detail, mitigation, or exploit information.

    00000199
    56.5K followersView on X

Explore more