Indutny maintains the elliptic library, a focused cryptographic component widely embedded in JavaScript and Node.js applications for elliptic-curve operations. Vulnerabilities affecting this vendor skew toward serious outcomes and concentrate on core cryptographic-verification weaknesses—including improper signature validation, length-parameter inconsistencies, and integer overflows—that can undermine the security of any downstream application relying on the library for authentication or key exchange. Defenders should treat updates to this library as high-priority and verify that applications bundling it are rebuilt and redeployed promptly; live severity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Indutny over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-48949CRITICAL The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(sig.eddsa.curve.n) || sig.S().isNeg()" validation. | Oct 10, 2024 | 9.1 | 29 | NO | NO |
CVE-2020-28498MEDIUM The package elliptic before 6.5.4 are vulnerable to Cryptographic Issues via the secp256k1 implementation in elliptic/ec/key.js. There is no check to confirm that the public key po | Feb 2, 2021 | 6.8 | 23 | NO | NO |
CVE-2020-13822HIGH The Elliptic package 6.5.2 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' bytes, or integer overflows. This could conceivably have a secur | Jun 4, 2020 | 7.7 | 20 | NO | NO |
CVE-2024-48948MEDIUM The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading 0 bytes and when the | Oct 15, 2024 | 4.8 | 19 | NO | NO |
CVE-2024-42460MEDIUM In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because there is a missing check for whether the leading bit of r and s is zero. | Aug 2, 2024 | 5.3 | 17 | NO | NO |
CVE-2024-42459MEDIUM In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature length check, and thus zero-valued bytes can be removed or appen | Aug 2, 2024 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Indutny.
Media articles that mention a CVE ID that affects a product developed by Indutny — matched by CVE ID, not by vendor name.