CRITICAL 9.1 npm
sm-crypto Affected by Private Key Recovery in SM2-PKE
GHSA-pgx9-497m-6c4v · CVE-2026-23966
Published · Modified
Description
Summary
A private key recovery vulnerability exists in the SM2 decryption logic of sm-crypto. By interacting with the SM2 decryption interface multiple times, an attacker can fully recover the private key within approximately several hundred interactions.
Credit
This vulnerability was discovered by:
- XlabAI Team of Tencent Xuanwu Lab
- Atuin Automated Vulnerability Discovery Engine
Ready to move
Start Securing
Free, no credit card | First findings in minutes