Reports

One line per issue, newest first. Severity is the report's overall rating; click an issue for the full report, including reproduction steps.

dateseveritycandidatefamilyissue
2026-09-21CriticalEijen hash-09Symmetric (sponge, Sponge-F)Trivial collisions in all Eijen implementations
2026-09-21CriticalMasterCube hash-17Symmetric (sponge, AndRX permutation)Trivial collisions at every rate boundary
2026-09-21CriticalAigis-Enc+ kem-01Lattice (Module-LWE)Ineffective implicit rejection breaks IND-CCA security
2026-09-21CriticalCheetahKEM kem-09Lattice (Ring/Module-LWE)Partial rejection mask leaks the candidate shared secret
2026-09-21CriticalHEP-QC kem-17Code-based (quasi-cyclic)Publicly reproducible secret keys
2026-09-21CriticalLoongKEM kem-18Lattice (LWE)Partial rejection mask leaks the candidate shared secret
2026-09-21CriticalPolar-KEM kem-29Lattice (polar-code-defined)The submission ships a complete public-key-only break
2026-09-21CriticalAFS-KEX kex-02Lattice (Module-LWE AKE)The ephemeral key is generated once as long-term state
2026-09-21CriticalCreTAKE kex-03Lattice (composite AKE: KEM + signature)Bits-versus-bytes error reduces the ephemeral secret to 64 bits
2026-09-21CriticalCEDRUS+C sign-03Hash-based (stateless)Hypertree index collapse causes repeated few-time keys
2026-09-21CriticalGalas sign-12Symmetric (MPC/VOLE-in-the-Head)Publicly reproducible signing keys
2026-09-21CriticalMORNING-ATLAS sign-15Lattice (Module-LWR, Fiat-Shamir)Returned-length error causes an out-of-bounds heap disclosure
2026-09-21CriticalMORNING-ATLAS sign-15Lattice (Module-LWR, Fiat-Shamir)Trivial hint-padding malleability violates SUF-CMA
2026-09-21CriticalSQIsign2D2 sign-25IsogenyVerifier accepts modified messages and an all-zero signature
2026-09-21CriticalUVW sign-32Multivariate (F3)Every signature is accepted
2026-09-21CriticalVDOO sign-33Multivariate (UOV family)Publicly reproducible signing keys
2026-09-21HighCHAMP hash-04Symmetric (Cayley graph / matrix products)Fixed-length outputs occupy only one determinant fiber
2026-09-21HighCHAMP hash-04Symmetric (Cayley graph / matrix products)Projective positive-word collision lead for CHAMP-512
2026-09-21HighMEGASCON hash-18Symmetric (sponge)The 384-bit digest is a prefix of the 512-bit digest
2026-09-21HighMOZI hash-20Symmetric (sponge)The 384-bit digest is a prefix of the 512-bit digest
2026-09-21HighMORNING-Scabbard kem-24Lattice (Module-LWR)Encryption omits the specified rounding constant
2026-09-21HighQCTM kem-32Code-based (quasi-cyclic twisted McEliece)Debug path retains the secret error vector
2026-09-21HighWeaverKEM kem-39Lattice (Module-LWR)PRF substream reuse violates the IND-CPA proof's independence premise
2026-09-21HighNEV-AKE kex-07Lattice (NTRU/Ring-LWE AKE)Both party identities are hard-wired to zero
2026-09-21HighAigis-Sig+ sign-01Lattice (Module-LWE/SIS, Fiat-Shamir)Trivial signature malleability violates SUF-CMA
2026-09-21HighCS sign-07Lattice (Module-LWE, Fiat-Shamir)Trivial signature malleability violates SUF-CMA