Description
The ECDSA implementation of the Elliptic package generates incorrect signatures if an interim value of ‘k’ (as computed based on step 3.2 of RFC 6979 https://datatracker.ietf.org/doc/html/rfc6979 ) has leading zeros and is susceptible to cryptanalysis, which can lead to secret key exposure.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 6.6.1
References
Could your website be exposed too?
SmartScanner can check your website for Elliptic Uses a Cryptographic Primitive with a Risky Implementation and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Elliptic Uses a Broken or Risky Cryptographic Algorithm - CVE-2020-28498
- Manifest Uses a One-Way Hash without a Salt - CVE-2025-27408
- @sveltejs/kit vulnerable to Cross-site Scripting via tracked search_params - CVE-2025-32388
- jquery-validation vulnerable to Cross-site Scripting - CVE-2025-3573


