← Vulnerability Intelligence

CVE-2024-42459

Elliptic's EDDSA missing signature length check

medium entropyCVE-2024-42459GHSA-f7q4-pwc6-w24p

Entropy / wallet impact

elliptic: In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature length check, and thus zero-valued bytes can be removed or appended.

Description

In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature length check, and thus zero-valued bytes can be removed or appended.

Affected

KindNameEcosystemVersions
packageellipticnpm>= 4.0.0, <= 6.5.6

CWE

CWE-347

Primary sources

Published
2024-08-02T09:31:35Z
Last modified
2025-11-04T16:51:35Z
First seen here
2026-08-18T15:11:37Z
CVSS
5.3 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N (ghsa)
Credibility
official_cve