Security Fixes
This version contains a fix for CVE-2026-28815: X-Wing HPKE Decapsulation Accepts Malformed Ciphertext Length. The X-Wing decapsulation path accepts attacker-controlled encapsulated ciphertext bytes without enforcing the required fixed ciphertext length. For more details see the advisory. We recommend updating to this release as soon as possible. (commit)
What's Changed
SemVer Patch
- Add missing input validation in X-Wing HPKE decapsulation by @josephnoir in bb4ba81
Full Changelog: 4.3.0...4.3.1