VYPR

crates.io package

risc0-circuit-rv32im

pkg:cargo/risc0-circuit-rv32im

Vulnerabilities (2)

  • CVE-2025-54873LowAug 6, 2025
    affected >= 2.0.0, < 3.0.0fixed 3.0.0

    RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture. RISC packages risc0-zkvm versions 2.0.0 through 2.1.0 and risc0-circuit-rv32im and risc0-circuit-rv32im-sys versions 2.0.0 through 2.0.4 contain vulnerabilitie

  • CVE-2025-52484LowJun 20, 2025
    affected >= 2.0.0, < 2.0.4fixed 2.0.4

    RISC Zero is a general computing platform based on zk-STARKs and the RISC-V microarchitecture. Due to a missing constraint in the rv32im circuit, any 3-register RISC-V instruction (including remu and divu) in risc0-zkvm 2.0.0, 2.0.1, and 2.0.2 are vulnerable to an attack by a mal