Executive brief
Plonky3 is a toolkit for building zero-knowledge proof systems. A flaw in its hashing mechanism allows different sets of data to produce the same digital fingerprint (hash collision) if the data lengths vary. This could potentially allow a malicious user to manipulate cryptographic proofs, though the risk is limited to specific scenarios where the amount of data being hashed is not fixed.
Technical details
The vulnerability exists in the `PaddingFreeSponge` construction within the `p3-symmetric` crate. When the number of elements to hash is not a multiple of the sponge's rate, the `hash_iter` function fails to apply proper domain separation or standard padding, instead padding with elements of the current state. This allows an attacker to construct two different input iterators of different lengths that result in an identical internal state and final hash. While systems with fixed-length inputs (like most STARKs) are unaffected, systems allowing variable-length inputs are vulnerable to hash collisions. The issue is addressed by introducing `Pad10Sponge`, which implements a secure 10-padding scheme.
Affected products
- Plonky3 p3-symmetric <= 0.5.2
Timeline
- 2026-04-16: advisory: GitHub Advisory GHSA-3g92-f9ch-qjcm published
- 2026-04-16: patched: Fix committed in repository