Security: JuneAndGreen/sm-crypto
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
DER signature decoder accepts non-minimal integer encodings, so the malleability CVE-2026-23967 describes is still reproducible at 0.5.4GHSA-75qp-p6cx-h553 published
Aug 4, 2026 by JuneAndGreenModerate -
SM2 verify hashes with the public key before validating it, so a malformed key throws instead of returning falseGHSA-xj7m-r97m-9h7w published
Jul 31, 2026 by JuneAndGreenModerate -
Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clockGHSA-vh45-f885-3848 published
Jul 23, 2026 by JuneAndGreenCritical -
Private Key Recovery in SM2-PKEGHSA-pgx9-497m-6c4v published
Jan 20, 2026 by JuneAndGreenCritical -
Signature Forgery in SM2-DSAGHSA-hpwg-xg7m-3p6m published
Jan 20, 2026 by JuneAndGreenHigh -
Signature Malleability in SM2-DSAGHSA-qv7w-v773-3xqm published
Jan 20, 2026 by JuneAndGreenHigh