Plonky3 is a toolkit for polynomial IOPs (PIOPs). Prior to versions 0.4.3 and 0.5.3, an attacker controlling prover-side observations can craft distinct transcripts that produce identical challenges, breaking the binding property of Fiat-Shamir. This issue has been patched in versions 0.4.3 and 0.5.3.
History

Wed, 10 Jun 2026 21:00:00 +0000

Type Values Removed Values Added
Description Plonky3 is a toolkit for polynomial IOPs (PIOPs). Prior to versions 0.4.3 and 0.5.3, an attacker controlling prover-side observations can craft distinct transcripts that produce identical challenges, breaking the binding property of Fiat-Shamir. This issue has been patched in versions 0.4.3 and 0.5.3.
Title Plonky3 MultiField32Challenger: transcript malleability and challenge entropy loss
Weaknesses CWE-1240
CWE-345
References
Metrics cvssV4_0

{'score': 8.9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-06-10T20:06:10.554Z

Reserved: 2026-05-15T20:11:54.585Z

Link: CVE-2026-46654

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-10T22:16:59.757

Modified: 2026-06-10T22:16:59.757

Link: CVE-2026-46654

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.