HIGH 7.5 npm
sm-crypto Affected by Signature Malleability in SM2-DSA
GHSA-qv7w-v773-3xqm · CVE-2026-23967
Published · Modified
Description
Summary
A signature malleability vulnerability exists in the SM2 signature verification logic of the sm-crypto library. An attacker can derive a new valid signature for a previously signed message from an existing signature.
Credit
This vulnerability was discovered by:
- XlabAI Team of Tencent Xuanwu Lab
- Atuin Automated Vulnerability Discovery Engine
Ready to move
Start Securing
Free, no credit card | First findings in minutes