Back to CVE List

CVE-2026-1229

LOW SEVERITY

CVSS Score & Metrics

Base Score
9.8 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Description

The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas.
ECDH and ECDSA signing relying on this curve are not affected.

The bug was fixed in v1.6.3 https://github.com/cloudflare/circl/releases/tag/v1.6.3 .

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-682
Source
NVD
Vendor
go
Product
github.com/cloudflare/circl

External References

Discussion (0)

Add Comment

No comments yet. Be the first!