Security and cryptography developments for 2026-10-01
Post-quantum cryptography discussions dominated the day, led by a contested claim of a quasipolynomial attack on Classic McEliece and supporting work on decoding records and signature plans. Several high-severity vulnerabilities were also disclosed in CPython SSL handling and Apache PLC4X industrial protocol drivers.
Contested quasipolynomial attack on Classic McEliece
A new eprint paper claims a quasipolynomial distinguisher and decryption attack against Classic McEliece. The pqc-forum hosted a 56-message debate involving Bernstein and other participants on the attack's validity, concrete costs, and implications for parameter choices. Readers following NIST PQC standardization should track whether the claimed complexity holds under further scrutiny.
CPython use-after-free in server-side SSLContext
CPython has been assigned CVE-2026-19445 for a use-after-free that occurs when an sni_callback switches server-side SSLContext objects. The flaw can allow a remote attacker to crash the process or trigger a pointer dereference. Operators running TLS servers in Python need to apply the forthcoming fix promptly.
Pre-authentication DoS in Apache PLC4X OPC UA
CVE-2026-102509 describes a high-severity pre-authentication resource-exhaustion vulnerability in the Apache PLC4X OPC UA driver and its Java SPI parser. Unauthenticated clients can force excessive resource consumption. Industrial control and SCADA integrations that embed PLC4X are directly affected.
Hostname check bypass in CPython wrap_bio
CVE-2026-19553 reports that SSLContext.wrap_bio() fails to validate the server_hostname parameter even when check_hostname is True. The omission permits a silent bypass of hostname verification. Applications relying on BIO-based TLS wrapping must treat the issue as a certificate validation failure.
NIST posts updated Round 3 onramp packages
NIST released updated Round 3 onramp packages for post-quantum signature candidates and invited community analysis of security and performance. The material is intended to inform discussion ahead of a 2027 conference. Cryptographers evaluating the onramp schemes now have refreshed reference implementations to examine.
New weight-64 quasi-cyclic syndrome decoding record
Researchers announced a new record for solving a weight-64 quasi-cyclic syndrome decoding challenge relevant to HQC, accompanied by a GPU implementation. Updated security estimates are expected to follow. The result supplies fresh data points for assessing the concrete hardness of HQC parameters.
Spoofable ADS discovery in Apache PLC4X
CVE-2026-102511 (CVSS 8.5) covers Apache PLC4X ADS discovery accepting spoofed UDP responses and deriving the connection target from them. An attacker can redirect subsequent connections to an arbitrary address. Deployments that perform ADS device discovery over untrusted networks face an immediate risk of connection hijacking.
NIST revises FN-DSA plan for fixed-point signing
NIST updated the FN-DSA plan inside FIPS 206 to require fixed-point arithmetic for signing operations and to enable exact known-answer test validation. The change aims to improve reproducibility and testability of the signature scheme. Implementers of FN-DSA should align their arithmetic choices with the revised guidance.