-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability manifests in the from_payload constructor of SignedPayload, as shown in the commit diff modifying src/ed25519.rs. The added MAX_INNER_PAYLOAD_LENGTH check and test case in tests/tests.rs explicitly target this function. The arithmetic operation's overflow potential is directly addressed by the patch, confirming this as the vulnerable entry point.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| stellar-strkey | rust | < 0.0.8 | 0.0.8 |
Ongoing coverage of React2Shell