Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Indutny

First CVE: Jun 4, 2020Active for: 6 yearsTotal CVEs: 6

Indutny maintains the elliptic library, a focused cryptographic component widely embedded in JavaScript and Node.js applications for elliptic-curve operations. Vulnerabilities affecting this vendor skew toward serious outcomes and concentrate on core cryptographic-verification weaknesses—including improper signature validation, length-parameter inconsistencies, and integer overflows—that can undermine the security of any downstream application relying on the library for authentication or key exchange. Defenders should treat updates to this library as high-priority and verify that applications bundling it are rebuilt and redeployed promptly; live severity and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 40% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Indutny over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 4, 2020
6 years ago
Most Recent CVE
Oct 15, 2024
647 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-48949CRITICAL
The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(sig.eddsa.curve.n) || sig.S().isNeg()" validation.
Oct 10, 20249.129NONO
CVE-2020-28498MEDIUM
The package elliptic before 6.5.4 are vulnerable to Cryptographic Issues via the secp256k1 implementation in elliptic/ec/key.js. There is no check to confirm that the public key po
Feb 2, 20216.823NONO
CVE-2020-13822HIGH
The Elliptic package 6.5.2 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' bytes, or integer overflows. This could conceivably have a secur
Jun 4, 20207.720NONO
CVE-2024-48948MEDIUM
The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading 0 bytes and when the
Oct 15, 20244.819NONO
CVE-2024-42460MEDIUM
In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because there is a missing check for whether the leading bit of r and s is zero.
Aug 2, 20245.317NONO
CVE-2024-42459MEDIUM
In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature length check, and thus zero-valued bytes can be removed or appen
Aug 2, 20245.317NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
67%
17%
17%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (50.0%)
High3 (50.0%)
Unknown0 (0.0%)
User Interaction
None6 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None6 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Indutny.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Indutny — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Indutny's Products

View all 2 CNAs →

Top CWEs