CVE-2026-6330
The ML-KEM ARM64 NEON ciphertext comparison only compares half of the input, breaking the Fujisaki-Okamoto transform's implicit rejection and weakening IND-CCA2 security on that code path. The constant-time comparison effectively ignored part of the re-encrypted ciphertext, so a decapsulating party could fail to detect a manipulated ciphertext and proceed without the standard's required implicit rejection.
- Affected products
- Ml-Kem
- Wolfssl
- < 5.9.2
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.2% (6th percentile)
- Weakness
- CWE-327
- NVD status
- Analyzed
- Published
- 2026-06-25
CVE-2026-6330 at NVD
1 known exploit for CVE-2026-6330
Proof-of-concept code and exploit modules indexed by Sploitus