We publish a GitHub security advisory for any releases whose CHANGELOG includes bug-fixes, and encourage our users to upgrade. The latest releases of the hpke-rs and hpke-rs-rust-crypto crates contain the following bug-fixes:
KemAlgorithm::TryFrom<u16> mapping where 0x004D incorrectly resolved to XWingDraft06 instead of XWingDraft06Obsolete.The issue fixed in #123 was first reported by Nadim Kobeissi. The issues fixed in #127 and #128 were first reported by Scott Arciszewski.
The issue fixed in #124 was first reported by Nadim Kobeissi.
{
"github_reviewed_at": "2026-02-13T20:05:10Z",
"severity": "MODERATE",
"cwe_ids": [
"CWE-190",
"CWE-20",
"CWE-697"
],
"github_reviewed": true,
"nvd_published_at": null
}