Ward Beullens found a practical key-recovery attack against Rainbow.
The level I parametersets are removed from liboqs starting from version 0.7.2.
Find the scientific details in Breaking Rainbow Takes a Weekend on a Laptop.
This means all the oqs::sig::Algorithm::RainbowI* variants are insecure.
{
"github_reviewed": true,
"severity": "HIGH",
"cwe_ids": [],
"nvd_published_at": null,
"github_reviewed_at": "2022-08-18T19:06:39Z"
}