← Back to browse · API

CVE-2022-37454

Severity
CRITICAL
CVSS
9.8
EPSS
0.05414
Risk score
41.09
CISA KEV
No
PoC
No
Published
2022-10-21
Modified
2025-05-08
First seen
2026-08-07
Aliases
EUVD-2023-1219, GHSA-6W4M-2XHG-2658, PYSEC-2026-504
Products
n/a:n/a
Sources
euvd EUVD-2023-1219

Description

The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.

References