GHSA-2w8x-224x-785m
HIGHCVE-2026-4258All versions of the package sjcl are vulnerable to Improper Verification of Cryptographic Signature due to missing point-on-curve validation in sjcl.ecc.basicKey.publicKey(). An attacker can recover a victim's ECDH private key by sending crafted off-curve public keys and observing ECDH outputs. The dhJavaEc() function directly returns the raw x-coordinate of the scalar multiplication result (no ha
- Affected
- <= 1.0.8
- Fixed in
- 1.0.9
- Weakness
- CWE-325
- Published
- 2026-03-17
- Source
- github