Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade ml-dsa to version 0.1.0-rc.5 or higher.
Affected versions of this package are vulnerable to Off-by-one Error in the use_hint function when handling signature verification. An attacker can cause valid signatures to be incorrectly rejected by crafting inputs where the decomposed low bits r0 equal zero, exploiting the off-by-two error in the calculation.