Vulnerabilities/

Elliptic Uses a Cryptographic Primitive with a Risky Implementation

Severity:
Low

Description

The ECDSA implementation of the Elliptic package generates incorrect signatures if an interim value of ‘k’ (as computed based on step 3.2 of RFC 6979 https://datatracker.ietf.org/doc/html/rfc6979 ) has leading zeros and is susceptible to cryptanalysis, which can lead to secret key exposure.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
elliptic
Anything's wrong? Let us know Last updated on January 09, 2026