A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.
CVSS Details
- CVSS 3.1 Base Score: 3.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade amazon-ssm-agent | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade amazon-ssm-agent | Jan 12, 2026 | Jun 10, 2025 |
| Debian | — | Upgrade golang-github-cloudflare-circl | Jul 23, 2026 | Jul 23, 2026 |
| Splunk | — | Upgrade Splunk Enterprise to version 9.3.10Upgrade Splunk Enterprise to version 10.0.4Upgrade Splunk Enterprise to version 10.2.1Upgrade Splunk Enterprise to version 9.4.9 | Mar 20, 2026 | Aug 6, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub