Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fc9h-whq2-v747 | Valid ECDSA signatures erroneously rejected in Elliptic |
Tue, 25 Nov 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 20 Jun 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Indutny
Indutny elliptic |
|
| CPEs | cpe:2.3:a:indutny:elliptic:6.5.7:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Indutny
Indutny elliptic |
Fri, 20 Dec 2024 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 05 Nov 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nodejs
Nodejs elliptic |
|
| Weaknesses | CWE-347 | |
| CPEs | cpe:2.3:a:nodejs:elliptic:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nodejs
Nodejs elliptic |
|
| Metrics |
cvssV3_1
|
ssvc
|
Wed, 16 Oct 2024 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | elliptic: ECDSA signature verification error may reject legitimate transactions | |
| Weaknesses | CWE-222 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Tue, 15 Oct 2024 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading 0 bytes and when the order of the elliptic curve's base point is smaller than the hash, because of an _truncateToN anomaly. This leads to valid signatures being rejected. Legitimate transactions or communications may be incorrectly flagged as invalid. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-25T15:41:32.403Z
Reserved: 2024-10-10T00:00:00.000Z
Link: CVE-2024-48948
Updated: 2024-12-20T13:06:45.340Z
Status : Modified
Published: 2024-10-15T14:15:05.280
Modified: 2025-11-25T16:16:05.680
Link: CVE-2024-48948
OpenCVE Enrichment
No data.
Github GHSA