Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-78p6-6878-8mj6 | SM2-PKE has Unchecked AffinePoint Decoding (unwrap) in decrypt() |
Thu, 22 Jan 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rustcrypto sm2 Elliptic Curve
|
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:rustcrypto:sm2_elliptic_curve:0.14.0:pre0:*:*:*:rust:*:* cpe:2.3:a:rustcrypto:sm2_elliptic_curve:0.14.0:rc0:*:*:*:rust:*:* |
|
| Vendors & Products |
Rustcrypto sm2 Elliptic Curve
|
Mon, 12 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 12 Jan 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rustcrypto
Rustcrypto elliptic-curves |
|
| Vendors & Products |
Rustcrypto
Rustcrypto elliptic-curves |
Sat, 10 Jan 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for representing various elliptic curve forms, scalars, points, and public/secret keys composed thereof. In versions 0.14.0-pre.0 and 0.14.0-rc.0, a denial-of-service vulnerability exists in the SM2 PKE decryption path where an invalid elliptic-curve point (C1) is decoded and the resulting value is unwrapped without checking. Specifically, AffinePoint::from_encoded_point(&encoded_c1) may return a None/CtOption::None when the supplied coordinates are syntactically valid but do not lie on the SM2 curve. The calling code previously used .unwrap(), causing a panic when presented with such input. This issue has been patched via commit 085b7be. | |
| Title | RustCrypto SM2-PKE has Unchecked AffinePoint Decoding (unwrap) in decrypt() | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-12T14:59:18.634Z
Reserved: 2026-01-08T19:23:09.856Z
Link: CVE-2026-22699
Updated: 2026-01-12T14:58:58.094Z
Status : Analyzed
Published: 2026-01-10T06:15:52.377
Modified: 2026-01-22T14:53:30.840
Link: CVE-2026-22699
No data.
OpenCVE Enrichment
Updated: 2026-04-18T07:15:25Z
Github GHSA