GHSA-5v5p-5xxr-9xf8MediumCVSS 6.2

An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA...

Published
September 9, 2026
Last Modified
September 9, 2026

🔗 CVE IDs covered (1)

📋 Description

An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P384,P521}.Dsa.pub_of_octets accept 0x00, the encoding of the point at infinity, as a public key. With that public key, signatures can be forged without a private key.

🔗 References (3)