CVE-2026-1229 is a critical vulnerability affecting the CombinedMult function within the CIRCL ecc/p384 package (secp384r1 curve) used by Cloudflare. It results in incorrect value generation for specific inputs, though ECDH and ECDSA signing are unaffected. With a CVSS score of 9.8 (CRITICAL), this vulnerability is remotely exploitable with low attack complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. The issue is categorized as CWE-682 (Incorrect Calculation). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE. A fix has been released in CIRCL v1.6.3.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.3CPE matchmatch criteria | cpe:2.3:a:cloudflare:circl:*:*:*:*:*:go:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:Amber
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.