Miggo Logo

GHSA-fr8m-434r-g3xp: gnark-crypto doesn't range check input values during ECDSA and EdDSA signature deserialization

5.1

CVSS Score
3.1

Basic Information

CVE ID
-
EPSS Score
-
Published
10/15/2025
Updated
10/15/2025
KEV Status
No
Technology
TechnologyGo

Technical Details

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Package NameEcosystemVulnerable VersionsFirst Patched Version
github.com/consensys/gnark-cryptogo< 0.12.00.12.0

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

### Imp**t *urin* **s*ri*liz*tion o* ***S* *n* ***S* si*n*tur*s *n*rk-*rypto *i* not ****k t**t t** v*lu*s *r* in t** r*n** `[*, n-*]` wit* `n` **in* t** *orr*spon*in* mo*ulus (*it**r **s* *i*l* mo*ulus in **s* o* `R` in ***S*, *n* s**l*r *i*l* mo*u

Reasoning

No *n*lysis *v*il**l*