The Secp256k1 Js Project maintains a JavaScript implementation of the secp256k1 elliptic-curve cryptography library, a foundational component for cryptocurrency and blockchain applications where correct implementation of cryptographic primitives is security-critical. Its narrow product scope means vulnerabilities here carry outsized importance to any downstream application that depends on this library for digital signature generation or validation. Current exposure counts and severity figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Secp256k1 Js Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-41340HIGH The secp256k1-js package before 1.1.0 for Node.js implements ECDSA without required r and s validation, leading to signature forgery. | Sep 24, 2022 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Secp256k1 Js Project.
Media articles that mention a CVE ID that affects a product developed by Secp256k1 Js Project — matched by CVE ID, not by vendor name.