216.73.216.6

CVE-2026-1229

· Published 24/02/2026 08:16 · Modified 24/02/2026 14:13

Labels: CVE-2026-1229 2026-02-24CVE-2026-1229CWE-682[email protected]

Essential information

Published
24/02/2026 08:16
Modified
24/02/2026 14:13
Author
Creator
CVSS
2.9 LOW (v3) 2.9 LOW (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signing relying on this curve are not affected. The bug was fixed in v1.6.3 https://github.com/cloudflare/circl/releases/tag/v1.6.3 .

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
cloudflare / circl cpe:2.3:a:cloudflare:circl:1.6.3:*:*:*:*:*:*:*
cloudflare / circl cpe:2.3:a:cloudflare:circl:*:*:*:*:*:*:*:*

References