Releases86
Frequency1 month 2 weeks
Last Release
EC cryptography

CVE History

CVEPublishedCVSS v3CVSS v2
7.7 HIGH6.8 MEDIUM

The Elliptic package 6.5.2 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' bytes, or integer overflows. This could conceivably have a security-relevant impact if an application relied on a single canonical signature.