CVE-2025-8556
Github.com/cloudflare/circl: circl-fourq: missing and wrong validation can lead to incorrect results
CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th
A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.
| CWE | CWE-1287 |
| Published | Aug 6, 2025 |
| Last Updated | Feb 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for
Be the first to know when new low vulnerabilities are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
Red Hat / Builds for Red Hat OpenShift
All versions affected Red Hat / Builds for Red Hat OpenShift
All versions affected Red Hat / Builds for Red Hat OpenShift
All versions affected Red Hat / Builds for Red Hat OpenShift
All versions affected Red Hat / Builds for Red Hat OpenShift
All versions affected Red Hat / Builds for Red Hat OpenShift
All versions affected Red Hat / Custom Metric Autoscaler operator for Red Hat Openshift
All versions affected Red Hat / Custom Metric Autoscaler operator for Red Hat Openshift
All versions affected Red Hat / Custom Metric Autoscaler operator for Red Hat Openshift
All versions affected Red Hat / Custom Metric Autoscaler operator for Red Hat Openshift
All versions affected Red Hat / Custom Metric Autoscaler operator for Red Hat Openshift
All versions affected Red Hat / Multicluster Global Hub
All versions affected Red Hat / OpenShift Pipelines
All versions affected Red Hat / OpenShift Pipelines
All versions affected Red Hat / OpenShift Pipelines
All versions affected Red Hat / OpenShift Pipelines
All versions affected Red Hat / OpenShift Pipelines
All versions affected Red Hat / OpenShift Pipelines
All versions affected Red Hat / OpenShift Pipelines
All versions affected Red Hat / OpenShift Pipelines
All versions affected Red Hat / OpenShift Pipelines
All versions affected Red Hat / OpenShift Pipelines
All versions affected Red Hat / OpenShift Pipelines
All versions affected Red Hat / OpenShift Pipelines
All versions affected Red Hat / OpenShift Pipelines
All versions affected Red Hat / OpenShift Pipelines
All versions affected Red Hat / OpenShift Pipelines
All versions affected Red Hat / OpenShift Pipelines
All versions affected Red Hat / OpenShift Pipelines
All versions affected Red Hat / OpenShift Pipelines
All versions affected Red Hat / OpenShift Pipelines
All versions affected Red Hat / OpenShift Pipelines
All versions affected Red Hat / OpenShift Pipelines
All versions affected Red Hat / OpenShift Pipelines
All versions affected Red Hat / OpenShift Pipelines
All versions affected Red Hat / OpenShift Pipelines
All versions affected Red Hat / OpenShift Pipelines
All versions affected Red Hat / OpenShift Pipelines
All versions affected Red Hat / OpenShift Pipelines
All versions affected Red Hat / OpenShift Serverless
All versions affected Red Hat / OpenShift Serverless
All versions affected Red Hat / OpenShift Serverless
All versions affected Red Hat / OpenShift Serverless
All versions affected Red Hat / OpenShift Service Mesh 3
All versions affected Red Hat / OpenShift Service Mesh 3
All versions affected Red Hat / OpenShift Service Mesh 3
All versions affected Red Hat / OpenShift Service Mesh 3
All versions affected Red Hat / OpenShift Service Mesh 3
All versions affected Red Hat / OpenShift Service Mesh 3
All versions affected Red Hat / OpenShift Service Mesh 3
All versions affected Red Hat / Red Hat Advanced Cluster Management for Kubernetes 2
All versions affected Red Hat / Red Hat Advanced Cluster Management for Kubernetes 2
All versions affected Red Hat / Red Hat Advanced Cluster Management for Kubernetes 2
All versions affected Red Hat / Red Hat Advanced Cluster Management for Kubernetes 2
All versions affected Red Hat / Red Hat Advanced Cluster Management for Kubernetes 2
All versions affected Red Hat / Red Hat Advanced Cluster Management for Kubernetes 2
All versions affected Red Hat / Red Hat Advanced Cluster Management for Kubernetes 2
All versions affected Red Hat / Red Hat Advanced Cluster Management for Kubernetes 2
All versions affected Red Hat / Red Hat Advanced Cluster Security 4
All versions affected Red Hat / Red Hat Advanced Cluster Security 4
All versions affected Red Hat / Red Hat Advanced Cluster Security 4
All versions affected Red Hat / Red Hat Advanced Cluster Security 4
All versions affected Red Hat / Red Hat Advanced Cluster Security 4
All versions affected Red Hat / Red Hat Advanced Cluster Security 4
All versions affected Red Hat / Red Hat Advanced Cluster Security 4
All versions affected Red Hat / Red Hat Advanced Cluster Security 4
All versions affected Red Hat / Red Hat Advanced Cluster Security 4
All versions affected Red Hat / Red Hat Advanced Cluster Security 4
All versions affected Red Hat / Red Hat Ceph Storage 5
All versions affected Red Hat / Red Hat Ceph Storage 5
All versions affected Red Hat / Red Hat Ceph Storage 6
All versions affected Red Hat / Red Hat Ceph Storage 6
All versions affected Red Hat / Red Hat Ceph Storage 8
All versions affected Red Hat / Red Hat Ceph Storage 8
All versions affected Red Hat / Red Hat Developer Hub
All versions affected Red Hat / Red Hat Developer Hub
All versions affected Red Hat / Red Hat Edge Manager preview
All versions affected Red Hat / Red Hat Edge Manager preview
All versions affected Red Hat / Red Hat Edge Manager preview
All versions affected Red Hat / Red Hat Edge Manager preview
All versions affected Red Hat / Red Hat Edge Manager preview
All versions affected Red Hat / Red Hat Edge Manager preview
All versions affected Red Hat / Red Hat Edge Manager preview
All versions affected Red Hat / Red Hat Edge Manager preview
All versions affected Red Hat / Red Hat Edge Manager preview
All versions affected Red Hat / Red Hat Edge Manager preview
All versions affected Red Hat / Red Hat Enterprise Linux 10
All versions affected Red Hat / Red Hat Enterprise Linux 9
All versions affected Red Hat / Red Hat Enterprise Linux AI (RHEL AI)
All versions affected Red Hat / Red Hat Enterprise Linux AI (RHEL AI)
All versions affected Red Hat / Red Hat Enterprise Linux AI (RHEL AI)
All versions affected Red Hat / Red Hat Enterprise Linux AI (RHEL AI)
All versions affected Red Hat / Red Hat Enterprise Linux AI (RHEL AI)
All versions affected Red Hat / Red Hat Enterprise Linux AI (RHEL AI)
All versions affected Red Hat / Red Hat Enterprise Linux AI (RHEL AI)
All versions affected Red Hat / Red Hat Enterprise Linux AI (RHEL AI)
All versions affected Red Hat / Red Hat Enterprise Linux AI (RHEL AI)
All versions affected Red Hat / Red Hat Enterprise Linux AI (RHEL AI)
All versions affected Red Hat / Red Hat OpenShift AI (RHOAI)
All versions affected Red Hat / Red Hat OpenShift AI (RHOAI)
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected Red Hat / Red Hat OpenShift Dev Workspaces Operator
All versions affected Red Hat / Red Hat OpenShift Dev Workspaces Operator
All versions affected Red Hat / Red Hat OpenShift Dev Workspaces Operator
All versions affected Red Hat / Red Hat OpenShift for Windows Containers
All versions affected Red Hat / Red Hat OpenShift for Windows Containers
All versions affected Red Hat / Red Hat OpenShift GitOps
All versions affected Red Hat / Red Hat OpenShift GitOps
All versions affected Red Hat / Red Hat OpenShift GitOps
All versions affected Red Hat / Red Hat OpenShift GitOps
All versions affected Red Hat / Red Hat OpenShift Virtualization 4
All versions affected Red Hat / Red Hat OpenStack Platform 16.2
All versions affected Red Hat / Red Hat OpenStack Platform 16.2
All versions affected Red Hat / Red Hat OpenStack Platform 16.2
All versions affected Red Hat / Red Hat OpenStack Platform 17.1
All versions affected Red Hat / Red Hat OpenStack Platform 17.1
All versions affected Red Hat / Red Hat OpenStack Platform 17.1
All versions affected Red Hat / Red Hat Trusted Application Pipeline
All versions affected Red Hat / Red Hat Trusted Artifact Signer
All versions affected Red Hat / Red Hat Trusted Artifact Signer
All versions affected Red Hat / Red Hat Trusted Artifact Signer
All versions affected Red Hat / Red Hat Trusted Artifact Signer
All versions affected Red Hat / Red Hat Trusted Artifact Signer
All versions affected Red Hat / Red Hat Trusted Artifact Signer
All versions affected Red Hat / Red Hat Trusted Artifact Signer
All versions affected Red Hat / Red Hat Trusted Artifact Signer
All versions affected Red Hat / Red Hat Trusted Profile Analyzer
All versions affected References
access.redhat.com: https://access.redhat.com/security/cve/CVE-2025-8556 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2371624 github.com: https://github.com/cloudflare/circl github.com: https://github.com/cloudflare/circl/security/advisories/GHSA-2x5j-vhc8-9cwm github.com: https://github.com/cloudflare/circl/tree/v1.6.1 botanica.software: https://www.botanica.software/blog/cryptographic-issues-in-cloudflares-circl-fourq-implementation news.ycombinator.com: https://news.ycombinator.com/item?id=45669593