sm-crypto Affected by Signature Malleability in SM2-DSA
High severity
GitHub Reviewed
Published
Jan 20, 2026
in
JuneAndGreen/sm-crypto
•
Updated Jan 21, 2026
Description
Published to the GitHub Advisory Database
Jan 21, 2026
Reviewed
Jan 21, 2026
Last updated
Jan 21, 2026
Summary
A signature malleability vulnerability exists in the SM2 signature verification logic of the sm-crypto library. An attacker can derive a new valid signature for a previously signed message from an existing signature.
Credit
This vulnerability was discovered by:
References