Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-66016

Опубликовано: 25 нояб. 2025
Источник: nvd
EPSS Низкий

Описание

CGGMP24 is a state-of-art ECDSA TSS protocol that supports 1-round signing (requires 3 preprocessing rounds), identifiable abort, and a key refresh protocol. Prior to version 0.6.3, there is a missing check in the ZK proof that enables an attack in which single malicious signer can reconstruct full private key. This issue has been patched in version 0.6.3, for full mitigation it is recommended to upgrade to cggmp24 version 0.7.0-alpha.2 as it contains more security checks.

EPSS

Процентиль: 7%
0.00027
Низкий

Дефекты

CWE-345

Связанные уязвимости

github
2 месяца назад

cggmp21 has a missing check in the ZK proof used in CGGMP21

EPSS

Процентиль: 7%
0.00027
Низкий

Дефекты

CWE-345