IsItPatchedInstant security status for any software version
← All products

CVE-2022-37454

CRITICAL severity · CVSS 9.8 · Integer overflow
9.8CVSS CRITICAL

Summary

The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.

Impact & exploitability

Attack vectorNetwork
Attack complexityLow
Privileges requiredNone
User interactionNone
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
Exploit probability (EPSS)1%

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products we track (2)

Recommendation

Apply the vendor fix promptly. Open any affected product above for its exact safe version.

Official patch: https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658 ↗

Last checked: Wed, 10 Jun 2026 22:18:30 UTC