HIGH 7.5 npm

sm-crypto Affected by Signature Malleability in SM2-DSA

GHSA-qv7w-v773-3xqm · CVE-2026-23967

Published · Modified

Description

Summary

A signature malleability vulnerability exists in the SM2 signature verification logic of the sm-crypto library. An attacker can derive a new valid signature for a previously signed message from an existing signature.

Credit

This vulnerability was discovered by:

  • XlabAI Team of Tencent Xuanwu Lab
  • Atuin Automated Vulnerability Discovery Engine

Ready to move

Start Securing

Free, no credit card | First findings in minutes