GHSA-rjr4-v43m-pxq6

Suggest an improvement
Source
https://github.com/advisories/GHSA-rjr4-v43m-pxq6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-rjr4-v43m-pxq6/GHSA-rjr4-v43m-pxq6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-rjr4-v43m-pxq6
Aliases
Published
2026-01-21T22:52:56Z
Modified
2026-02-22T23:20:39Z
Severity
  • 1.7 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U CVSS Calculator
Summary
Triton VM has a Soundness Vulnerability due to Improper Sampling of Randomness
Details

In affected versions of Triton VM, the verifier failed to correctly sample randomness in the FRI sub-protocol.

Malicious provers can exploit this to craft proofs for arbitrary statements that this verifier accepts as valid, undermining soundness.

Protocols that rely on proofs and the supplied verifier of the affected versions of Triton VM are completely broken. Protocols implementing their own verifier might be unaffected.

The flaw was corrected in commit 3a045d63, where the relevant randomness is sampled correctly.

Database specific
{
    "cwe_ids":  [
        "CWE-330"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-01-21T22:52:56Z",
    "nvd_published_at":  null,
    "severity":  "LOW"
}
References

Affected packages

crates.io / triton-vm

Package

Name
triton-vm
View open source insights on deps.dev
Purl
pkg:cargo/triton-vm

Affected ranges

Type
SEMVER
Events
Introduced
0.41.0
Fixed
2.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-rjr4-v43m-pxq6/GHSA-rjr4-v43m-pxq6.json"