← Vulnerability Intelligence

CVE-2024-42460

Elliptic's ECDSA missing check for whether leading bit of r and s is zero

medium entropyCVE-2024-42460GHSA-977x-g7h5-7qgw

Entropy / wallet impact

elliptic: In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because there is a missing check for whether the leading bit of r and s is zero.

Description

In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because there is a missing check for whether the leading bit of r and s is zero.

Affected

KindNameEcosystemVersions
packageellipticnpm>= 2.0.0, <= 6.5.6

CWE

CWE-130

Primary sources

Published
2024-08-02T09:31:35Z
Last modified
2025-11-04T16:52:45Z
First seen here
2026-08-18T15:11:37Z
CVSS
5.3 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N (ghsa)
Credibility
official_cve