Headline
GHSA-q3f4-9h4p-vgr3: secp256k1-js implements ECDSA without required r and s validation, leading to signature forgery
The secp256k1-js package before 1.1.0 for Node.js implements ECDSA without required r and s validation, leading to signature forgery.
secp256k1-js implements ECDSA without required r and s validation, leading to signature forgery
Moderate severity GitHub Reviewed Published Sep 25, 2022 • Updated Sep 27, 2022
Related news
CVE-2022-41340: Comparing 1.0.1...1.1.0 · lionello/secp256k1-js
The secp256k1-js package before 1.1.0 for Node.js implements ECDSA without required r and s validation, leading to signature forgery.