CVE-2026-44518: liboqs: XMSS Buffer Overread Bug

Published May 29, 2026
·
Updated

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS and XMSS^MT stateful signature verification code. When the verification function is called with a signature buffer shorter than the expected signature size for the given parameter set, the implementation does not validate the caller-supplied length and proceeds to read past the end of the buffer. The out-of-bounds bytes are consumed only as input to an internal hash computation and are not returned to the caller, so no oracle exists to leak their contents to an attacker. The primary observable effect is a possible crash (denial of service) of the verifying process if the read crosses into an unmapped memory page. This vulnerability is fixed in 0.16.0.

Affected Software

2 affected components
Open Quantum Safe liboqs<0.16.0
Openquantumsafe Liboqs<=0.15.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade liboqs XMSS/XMSS^MT to a version that resolves this vulnerability.

    Fixed in 0.16.0

Event History

May 29, 2026
CVE Published
via MITRE·06:07 PM
Data Sourced
via MITRE·06:07 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-44518?

CVE-2026-44518 has a severity rating of medium with a score of 5.3.

2

How do I fix CVE-2026-44518?

You can fix CVE-2026-44518 by applying the available patch provided in version 0.16.0 or later.

3

What impact does CVE-2026-44518 have on Open Quantum Safe liboqs?

CVE-2026-44518 can lead to an out-of-bounds read, potentially causing data leakage during the XMSS signature verification process.

4

Which versions of liboqs are affected by CVE-2026-44518?

CVE-2026-44518 affects all versions of liboqs prior to 0.16.0.

5

Is there a workaround for CVE-2026-44518?

There is no specific workaround for CVE-2026-44518; the recommended action is to update to the patched version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203