CVE-2019-16143: BLAKE2 BLAKE2-Rust
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
An issue was discovered in the blake2 crate before 0.8.1 for Rust. The BLAKE2b and BLAKE2s algorithms, when used with HMAC, produce incorrect results because the block sizes are half of the required sizes.
Affected products
- BLAKE2 BLAKE2-Rust: before 0.8.1 (fixed in 0.8.1)
Published 2019-09-09. Last modified 2026-06-17.