ML-KEM is mathematically sound. The library shipping it wasn’t — and for eight months, nobody noticed.
In August, researchers (including Anthropic’s Nicholas Carlini) disclosed two implementation flaws in wolfSSL’s hand-optimized ML-KEM decapsulation code. Both are now patched, but the mechanism deserves every CISO’s attention:
In August, researchers (including Anthropic’s Nicholas Carlini) disclosed two implementation flaws…” (which is already done well in the text!
𝗧𝗵𝗲 𝗯𝘂𝗴: wolfSSL’s SIMD assembly for the Fujisaki–Okamoto ciphertext-comparison check skipped bytes — the AVX2 path verified only 1,536 of 1,568 bytes on ML-KEM-1024; the ARM64 NEON path missed roughly half.
𝗧𝗵𝗲 𝗰𝗼𝗻𝘀𝗲𝗾𝘂𝗲𝗻𝗰𝗲: those skipped bytes carry decryption noise that’s a linear function of the secret key. An attacker who can submit malformed ciphertexts and observe decapsulation behavior can solve for that key via ordinary least squares — no lattice reduction needed. Reported success rate: 98%+, in a few hundred chosen ciphertexts.
𝗧𝗵𝗲 𝘀𝗰𝗼𝗽𝗲: CVE-2026-10097 (CVSS 8.3) and CVE-2026-6330 affected wolfSSL 5.7.0–5.9.1, fixed in 5.9.2. Static-key deployments carried real risk; ephemeral TLS sessions saw only a weaker distinguishing break.
𝗧𝗵𝗲 𝗹𝗲𝘀𝘀𝗼𝗻: “NIST-standardized algorithm” and “correctly implemented algorithm” are two separate claims. The FO comparison step is now a first-order audit target for anyone reviewing PQC libraries in production.
𝗕𝗼𝘁𝘁𝗼𝗺 𝗟𝗶𝗻𝗲: Standardization solved the math problem. It didn’t solve the implementation problem — that’s on your team, your vendors, and whoever is auditing the crypto libraries actually running in your stack.
Is implementation-level review part of your PQC migration plan, or are you trusting library defaults?
#PostQuantumCryptography #PQC #Cybersecurity #CryptoAgility #MLKEM #CISO #QuantumSafe #InfoSec #TLS #NIST
Sources:
– Incomplete Ciphertext Comparison in ML-KEM: From an IND-CCA2 Break to Key Recovery (IACR ePrint 2026/1682): https://www.google.com/url?q=
– CVE-2026-10097 record: https://www.google.com/url?q=
– wolfSSL ML-KEM Key Recovery Bug analysis: https://www.google.com/url?q=
