CVE-2026-4258 is a high-severity vulnerability (CVSS 7.5) affecting all versions of the sjcl package, stemming from improper cryptographic signature verification due to missing point-on-curve validation. This flaw allows an unauthenticated network attacker to recover a victim's ECDH private key by sending crafted public keys and observing ECDH outputs. The vulnerability has a high confidentiality impact, providing a plaintext oracle for private key recovery. While there is no public exploit code available and it is not currently listed on CISA KEV, it is on the Hot List, indicating significant attention and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.8CPE matchmatch criteria | cpe:2.3:a:bitwiseshiftleft:stanford_javascript_crypto_library:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.