216.73.217.22

CVE-2026-4258

· Published 17/03/2026 06:16 · Modified 17/03/2026 14:20

Labels: CVE-2026-4258 2026-03-17CVE-2026-4258CWE-325CWE-347[email protected]

Essential information

Published
17/03/2026 06:16
Modified
17/03/2026 14:20
Author
Creator
CVSS
7.7 HIGH (v3) 7.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

All versions of the package sjcl are vulnerable to Improper Verification of Cryptographic Signature due to missing point-on-curve validation in sjcl.ecc.basicKey.publicKey(). An attacker can recover a victim's ECDH private key by sending crafted off-curve public keys and observing ECDH outputs. The dhJavaEc() function directly returns the raw x-coordinate of the scalar multiplication result (no hashing), providing a plaintext oracle without requiring any decryption feedback.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
* / sjcl cpe:2.3:a:*:sjcl:*:*:*:*:*:*:*:*

References