CVE-2026-55174
MEDIUM
5,9
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: high
Availability: none
Description
AI Translation Available
UltrafastSecp256k1 is a high-performance, multi-backend secp256k1 engine with reproducible audit evidence, compatibility shims, and profile-based review scopes. Prior to version 4.2.0, UltrafastSecp256k1's ECDSA adaptor pre-signature verification accepts forged adaptor pre-signatures whose 'r' value is not cryptographically bound to the adaptor point 'T'. This issue has been patched in version 4.2.0.
345
Insufficient Verification of Data Authenticity
DraftCommon Consequences
Security Scopes Affected:
Integrity
Other
Potential Impacts:
Varies By Context
Unexpected State
Applicable Platforms
Technologies:
ICS/OT
347
Improper Verification of Cryptographic Signature
DraftCommon Consequences
Security Scopes Affected:
Access Control
Integrity
Confidentiality
Potential Impacts:
Gain Privileges Or Assume Identity
Modify Application Data
Execute Unauthorized Code Or Commands
Applicable Platforms
All platforms may be affected
https://github.com/shrec/UltrafastSecp256k1/commit/5478ef566c6af91b48a45c0c61f1…
https://github.com/shrec/UltrafastSecp256k1/releases/tag/v4.2.0
https://github.com/shrec/UltrafastSecp256k1/releases/tag/v4.2.1
https://github.com/shrec/UltrafastSecp256k1/security/advisories/GHSA-c7q2-gv3g-…