Starkbank provides cryptographic libraries for digital signature operations across multiple programming languages, with its exposure centered on a recurring weakness class involving improper verification of cryptographic signatures that undermines the authenticity guarantees the libraries are designed to provide. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Starkbank over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-43569CRITICAL The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary | Nov 9, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-43568CRITICAL The verify function in the Stark Bank Elixir ECDSA library (ecdsa-elixir) 1.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitra | Nov 9, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-43572CRITICAL The verify function in the Stark Bank Python ECDSA library (aka starkbank-escada or ecdsa-python) before 2.0.1 fails to check that the signature is non-zero, which allows attackers | Nov 9, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-43571CRITICAL The verify function in the Stark Bank Node.js ECDSA library (ecdsa-node) 1.1.2 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrar | Nov 9, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-43570CRITICAL The verify function in the Stark Bank Java ECDSA library (ecdsa-java) 1.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary m | Nov 9, 2021 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Starkbank.
Media articles that mention a CVE ID that affects a product developed by Starkbank — matched by CVE ID, not by vendor name.