CVE-2026-46654

Plonky3 is a toolkit for polynomial IOPs (PIOPs). Prior to versions 0.4.3 and 0.5.3, an attacker controlling prover-side observations can craft distinct transcripts that produce identical challenges, breaking the binding property of Fiat-Shamir. This issue has been patched in versions 0.4.3 and 0.5.3.
CVSS

No CVSS.

Configurations

No configuration.

History

10 Jun 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-10 22:16

Updated : 2026-06-11 15:36


NVD link : CVE-2026-46654

Mitre link : CVE-2026-46654

CVE.ORG link : CVE-2026-46654


JSON object : View

Products Affected

No product.

CWE
CWE-345

Insufficient Verification of Data Authenticity

CWE-1240

Use of a Cryptographic Primitive with a Risky Implementation