← Vulnerability Intelligence

CVE-2024-42461

Elliptic allows BER-encoded signatures

medium entropyGHSA-49q7-c7j4-3p7mCVE-2024-42461

Entropy / wallet impact

elliptic: In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.

Description

In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.

Affected

KindNameEcosystemVersions
packageellipticnpm>= 5.2.1, <= 6.5.6

CWE

CWE-347

Primary sources

Published
2024-08-02T09:31:35Z
Last modified
2025-11-04T16:52:52Z
First seen here
2026-08-18T15:11:37Z
CVSS
5.3 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N (ghsa)
Credibility
official_cve