Логотип exploitDog
bind:CVE-2026-23966
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-23966

Количество 2

Количество 2

nvd логотип

CVE-2026-23966

18 дней назад

sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A private key recovery vulnerability exists in the SM2 decryption logic of sm-crypto prior to version 0.3.14. By interacting with the SM2 decryption interface multiple times, an attacker can fully recover the private key within approximately several hundred interactions. Version 0.3.14 patches the issue.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-pgx9-497m-6c4v

18 дней назад

sm-crypto Affected by Private Key Recovery in SM2-PKE

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-23966

sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A private key recovery vulnerability exists in the SM2 decryption logic of sm-crypto prior to version 0.3.14. By interacting with the SM2 decryption interface multiple times, an attacker can fully recover the private key within approximately several hundred interactions. Version 0.3.14 patches the issue.

CVSS3: 9.1
0%
Низкий
18 дней назад
github логотип
GHSA-pgx9-497m-6c4v

sm-crypto Affected by Private Key Recovery in SM2-PKE

CVSS3: 9.1
0%
Низкий
18 дней назад

Уязвимостей на страницу