CVE-2024-48948 is a medium-severity vulnerability affecting the Elliptic package 6.5.7 for Node.js, specifically its ECDSA implementation. It causes valid signatures to be incorrectly rejected if the hash contains at least four leading zero bytes and the elliptic curve's base point order is smaller than the hash, due to a _truncateToN anomaly. This can lead to legitimate transactions or communications being flagged as invalid. The vulnerability has a CVSS score of 4.8 (Medium) with a network attack vector and high attack complexity, potentially impacting integrity and availability. There is no evidence of active exploitation, no public exploit code, and minimal community discussion, though it has received some media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.5.7CPE matchmatch criteria | cpe:2.3:a:indutny:elliptic:6.5.7:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Third-Party Package Updates in Enterprise Security 8.1.0 - July 2025
Jul 30, 2025Third-Party Package Updates in Splunk Machine Learning Toolkit - June 2025
Jun 12, 2025Valid ECDSA signatures erroneously rejected in Elliptic
Oct 15, 2024elliptic: ECDSA signature verification error may reject legitimate transactions
Oct 15, 2024