Keypair Project maintains a specialized cryptographic library focused on key-agreement and key-derivation operations, serving a niche but security-critical function in applications requiring authenticated key exchange. The observed vulnerability signal centers on improper seed handling in pseudo-random number generation, a weakness class that directly undermines the cryptographic properties the library is designed to provide. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Keypair Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-41117CRITICAL keypair is a a RSA PEM key generator written in javascript. keypair implements a lot of cryptographic primitives on its own or by borrowing from other libraries where possible, inc | Oct 11, 2021 | 9.1 | 30 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Keypair Project.
Media articles that mention a CVE ID that affects a product developed by Keypair Project — matched by CVE ID, not by vendor name.