CVE-2023-26556 is a critical timing side-channel vulnerability in io.finnet tss-lib versions prior to 2.0.0, also affecting bnb-chain/tss-lib and thorchain/tss. The flaw stems from its reliance on Go crypto/elliptic's non-constant time scalar-multiplication implementation, specifically allowing secret key leakage in ecdsa/keygen/round_2.go. With a CVSS score of 9.1 (CRITICAL), this vulnerability is remotely exploitable with low attack complexity, potentially leading to complete confidentiality and integrity compromise. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.0CPE matchmatch criteria | cpe:2.3:a:iofinnet:tss-lib:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.