7.5
CVE-2026-22700
- EPSS 0.1%
- Veröffentlicht 10.01.2026 05:17:25
- Zuletzt bearbeitet 22.01.2026 14:53:48
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for representing various elliptic curve forms, scalars, points, and public/secret keys composed thereof. In versions 0.14.0-pre.0 and 0.14.0-rc.0, a denial-of-service vulnerability exists in the SM2 public-key encryption (PKE) implementation: the decrypt() path performs unchecked slice::split_at operations on input buffers derived from untrusted ciphertext. An attacker can submit short/undersized ciphertext or carefully-crafted DER-encoded structures to trigger bounds-check panics (Rust unwinding) which crash the calling thread or process. This issue has been patched via commit e60e991.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rustcrypto ≫ Sm2 Elliptic Curve Version0.14.0 Updatepre0 SwPlatformrust
Rustcrypto ≫ Sm2 Elliptic Curve Version0.14.0 Updaterc0 SwPlatformrust
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.1% | 0.282 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.