Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6277 | The implementation of EdDSA in EdDSA-Java (aka ed25519-java) through 0.3.0 exhibits signature malleability and does not satisfy the SUF-CMA (Strong Existential Unforgeability under Chosen Message Attacks) property. This allows attackers to create new valid signatures different from previous signatures for a known message. |
Github GHSA |
GHSA-p53j-g8pw-4w5f | Ed25519 Signature Malleability in ed25519-java Due to Missing Scalar Range Check |
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 18 Mar 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Mar 2025 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The implementation of EdDSA in EdDSA-Java (aka ed25519-java) through 0.3.0 exhibits signature malleability and does not satisfy the SUF-CMA (Strong Existential Unforgeability under Chosen Message Attacks) property. This allows attackers to create new valid signatures different from previous signatures for a known message. | |
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-18T16:22:08.617Z
Reserved: 2025-03-13T00:00:00.000Z
Link: CVE-2020-36843
Updated: 2025-03-18T16:22:04.608Z
Status : Deferred
Published: 2025-03-13T06:15:34.043
Modified: 2026-04-15T00:35:42.020
Link: CVE-2020-36843
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA