The Elliptic Project develops a cryptographic library focused on elliptic-curve operations, with its disclosed vulnerabilities centering on improper cryptographic-signature verification. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Elliptic Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-42461CRITICAL In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed. | Aug 2, 2024 | 9.1 | 28 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Elliptic Project.
Media articles that mention a CVE ID that affects a product developed by Elliptic Project — matched by CVE ID, not by vendor name.