VYPR

Caliptra Core Runtime Firmware

by Chipsalliance

Source repositories

CVEs (1)

  • CVE-2026-6458MedJun 24, 2026
    risk 0.26cvss epss 0.00

    Missing cryptographic step in Caliptra Core Firmware (aes_256_gcm_update module) results in an incorrect GCM authentication tag. When the streaming AES-256-GCM API is used with empty AAD, the hardware GHASH accumulator state is not saved after the first update call, causing the…