Consensys develops cryptographic and blockchain infrastructure components, notably the gnark zero-knowledge proof library and associated cryptographic toolkit, that see deployment across distributed ledger and privacy-critical applications. Vulnerabilities affecting this vendor skew toward serious outcomes and cluster around sensitive-information exposure, resource-consumption flaws, and cryptographic verification weaknesses that reflect the complexity of proving and validating high-assurance computations. Defenders integrating these libraries should track updates closely given the vendor's prominence in zero-knowledge and privacy infrastructure; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Consensys over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-57801CRITICAL gnark is a zero-knowledge proof system framework. In versions prior to 0.14.0, the Verify function in eddsa.go and ecdsa.go used the S value from a signature without asserting that | Aug 22, 2025 | 9.1 | 29 | NO | NO |
CVE-2023-44273CRITICAL Consensys gnark-crypto through 0.11.2 allows Signature Malleability. This occurs because deserialisation of EdDSA and ECDSA signatures does not ensure that the data is in a certain | Sep 28, 2023 | 9.8 | 26 | NO | NO |
CVE-2025-58157HIGH gnark is a zero-knowledge proof system framework. In version 0.12.0, there is a potential denial of service vulnerability when computing scalar multiplication is using the fake-GLV | Aug 29, 2025 | 7.5 | 25 | NO | NO |
CVE-2024-45040MEDIUM gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.11.0, commitments to private witnesses in Groth16 as implemented break the zero | Sep 6, 2024 | 5.9 | 21 | NO | NO |
CVE-2024-45039MEDIUM gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Versions prior to 0.11.0 have a soundness issue - in case of multiple commitments used inside the | Sep 6, 2024 | 6.2 | 21 | NO | NO |
CVE-2024-50354MEDIUM gnark is a fast zk-SNARK library that offers a high-level API to design circuits. In gnark 0.11.0 and earlier, deserialization of Groth16 verification keys allocate excessive memor | Oct 31, 2024 | 5.5 | 19 | NO | NO |
CVE-2024-23688MEDIUM Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session. which should ideally be unique for every message. The node's private key isn't comp | Jan 19, 2024 | 5.3 | 18 | NO | NO |
CVE-2023-44378MEDIUM gnark is a zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.9.0, for some in-circuit values, it is possible to construct two valid decomposition | Oct 9, 2023 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Consensys.
Media articles that mention a CVE ID that affects a product developed by Consensys — matched by CVE ID, not by vendor name.