CVE-2024-48948

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/10/2024
Last modified:
25/11/2025

Description

The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading 0 bytes and when the order of the elliptic curve's base point is smaller than the hash, because of an _truncateToN anomaly. This leads to valid signatures being rejected. Legitimate transactions or communications may be incorrectly flagged as invalid.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:indutny:elliptic:6.5.7:*:*:*:*:node.js:*:*