Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-q3f4-9h4p-vgr3: secp256k1-js implements ECDSA without required r and s validation, leading to signature forgery

The secp256k1-js package before 1.1.0 for Node.js implements ECDSA without required r and s validation, leading to signature forgery.

ghsa
#nodejs#js#git

secp256k1-js implements ECDSA without required r and s validation, leading to signature forgery

Moderate severity GitHub Reviewed Published Sep 25, 2022 • Updated Sep 27, 2022

Related news

CVE-2022-41340: Comparing 1.0.1...1.1.0 · lionello/secp256k1-js

The secp256k1-js package before 1.1.0 for Node.js implements ECDSA without required r and s validation, leading to signature forgery.