CVE-2025-12888

Vulnerability in X25519 constant-time cryptographic implementations due to timing side channels introduced by compiler optimizations and CPU architecture limitations, specifically with the Xtensa-based ESP32 chips. If targeting Xtensa it is recommended to use the low memory implementations of X25519, which is now turned on as the default for Xtensa.
CVSS

No CVSS.

Configurations

No configuration.

History

21 Nov 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-21 23:15

Updated : 2025-11-25 22:16


NVD link : CVE-2025-12888

Mitre link : CVE-2025-12888

CVE.ORG link : CVE-2025-12888


JSON object : View

Products Affected

No product.

CWE
CWE-203

Observable Discrepancy