CVE-2022-41340
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/09/2022
Last modified:
22/05/2025
Description
The secp256k1-js package before 1.1.0 for Node.js implements ECDSA without required r and s validation, leading to signature forgery.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:secp256k1-js_project:secp256k1-js:*:*:*:*:*:node.js:*:* | 1.1.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/lionello/secp256k1-js/commit/302800f0370b42e360a33774bb808274ac729c2e
- https://github.com/lionello/secp256k1-js/compare/1.0.1...1.1.0
- https://github.com/lionello/secp256k1-js/issues/11
- https://www.npmjs.com/package/%40lionello/secp256k1-js
- https://github.com/lionello/secp256k1-js/commit/302800f0370b42e360a33774bb808274ac729c2e
- https://github.com/lionello/secp256k1-js/compare/1.0.1...1.1.0
- https://github.com/lionello/secp256k1-js/issues/11
- https://www.npmjs.com/package/%40lionello/secp256k1-js



