Логотип exploitDog
bind:CVE-2025-66016
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-66016

Количество 2

Количество 2

nvd логотип

CVE-2025-66016

3 месяца назад

CGGMP24 is a state-of-art ECDSA TSS protocol that supports 1-round signing (requires 3 preprocessing rounds), identifiable abort, and a key refresh protocol. Prior to version 0.6.3, there is a missing check in the ZK proof that enables an attack in which single malicious signer can reconstruct full private key. This issue has been patched in version 0.6.3, for full mitigation it is recommended to upgrade to cggmp24 version 0.7.0-alpha.2 as it contains more security checks.

EPSS: Низкий
github логотип

GHSA-m95p-425x-x889

3 месяца назад

cggmp21 has a missing check in the ZK proof used in CGGMP21

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-66016

CGGMP24 is a state-of-art ECDSA TSS protocol that supports 1-round signing (requires 3 preprocessing rounds), identifiable abort, and a key refresh protocol. Prior to version 0.6.3, there is a missing check in the ZK proof that enables an attack in which single malicious signer can reconstruct full private key. This issue has been patched in version 0.6.3, for full mitigation it is recommended to upgrade to cggmp24 version 0.7.0-alpha.2 as it contains more security checks.

0%
Низкий
3 месяца назад
github логотип
GHSA-m95p-425x-x889

cggmp21 has a missing check in the ZK proof used in CGGMP21

0%
Низкий
3 месяца назад

Уязвимостей на страницу