CVE-2019-16143

CRITICAL

blake2-rust < 0.8.1 - Use of a Broken or Risky Cryptographic Algorithm

Title source: llm
STIX 2.1

Description

An issue was discovered in the blake2 crate before 0.8.1 for Rust. The BLAKE2b and BLAKE2s algorithms, when used with HMAC, produce incorrect results because the block sizes are half of the required sizes.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://rustsec.org/advisories/RUSTSEC-2019-0019.html

Scores

CVSS v3 9.8
EPSS 0.0093
EPSS Percentile 55.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-327
Status published
Products (2)
blake2/blake2-rust < 0.8.1
crates.io/blake2 0 - 0.8.1crates.io
Published Sep 09, 2019
Tracked Since Feb 18, 2026