CVE-2026-22698 describes a critical vulnerability in the RustCrypto: Elliptic Curves library, specifically affecting versions 0.14.0-pre.0 and 0.14.0-rc.0. The flaw resides in the SM2 Public Key Encryption (PKE) implementation, where a unit mismatch error causes the ephemeral nonce k to be generated with only 32 bits of randomness instead of the expected 256 bits. This significantly reduces the cryptographic strength from a 128-bit level to a trivial 16-bit level. The vulnerability carries a HIGH severity CVSS score of 8.7, indicating it is easily exploitable over the network with low attack complexity and no user interaction required. An attacker can recover the nonce k and decrypt any ciphertext given only the public key and ciphertext, leading to a complete loss of confidentiality. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, suggesting low public awareness of this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.14.0CPE matchmatch criteria | cpe:2.3:a:rustcrypto:sm2_elliptic_curve:0.14.0:pre0:*:*:*:rust:*:* | ||
0.14.0CPE matchmatch criteria | cpe:2.3:a:rustcrypto:sm2_elliptic_curve:0.14.0:rc0:*:*:*:rust:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.