cggmp21
Activity
- Latest release
- 9mo ago
- Total releases
- 15
- Cadence
- ~41 days
- Last 12 months
- 1
Details
- License
- MIT OR Apache-2.0
- First release
- Oct 06, 2022
| Version | Released | |
|---|---|---|
0.6.3
unknown
1 CVE
CVE-2025-66017
GHSA-8frv-q972-9rq5
RUSTSEC-2025-0127
RUSTSEC-2025-0128
Nov 25, 2025
cggmp24 and cggmp21 are vulnerable to signature forgery through altered presignatures
High
Network
Low
None
None
ImpactThis attack is against presignatures used in very specific context:
Patches
WorkaroundsUsers can continue using un-patched versions of library as long as they don't use presignatures in said scenarios where it weakens system security. To be sure, migrate to patched version that excludes presignatures from being used in such scenarios. ReferencesRead this blog post to learn more. References
Updated Nov 27, 2025 · Source: OSV.dev |
0.6.3
unknown
Dependencies (21)
+ 13 more |
|
0.6.2
unknown
2 CVEs
CVE-2025-66017
GHSA-8frv-q972-9rq5
RUSTSEC-2025-0127
RUSTSEC-2025-0128
Nov 25, 2025
cggmp24 and cggmp21 are vulnerable to signature forgery through altered presignatures
High
Network
Low
None
None
ImpactThis attack is against presignatures used in very specific context:
Patches
WorkaroundsUsers can continue using un-patched versions of library as long as they don't use presignatures in said scenarios where it weakens system security. To be sure, migrate to patched version that excludes presignatures from being used in such scenarios. ReferencesRead this blog post to learn more. References
Updated Nov 27, 2025 · Source: OSV.dev
CVE-2025-66016
GHSA-m95p-425x-x889
RUSTSEC-2025-0129
RUSTSEC-2025-0130
Nov 25, 2025
cggmp21 has a missing check in the ZK proof used in CGGMP21
Critical
Network
Low
None
None
Impactcggmp21 concerns a missing check in the ZK proof that enables an attack in which a single malicious signer can reconstruct full private key. Patches
WorkaroundsUpdate to However, for full mitigation, users will need to upgrade to ResourcesRead this blog post to learn more. Fixed in
0.6.3
References
Updated Nov 27, 2025 · Source: OSV.dev |
0.6.2
unknown
Dependencies (21)
+ 13 more |
|
0.6.1
unknown
2 CVEs
CVE-2025-66017
GHSA-8frv-q972-9rq5
RUSTSEC-2025-0127
RUSTSEC-2025-0128
Nov 25, 2025
cggmp24 and cggmp21 are vulnerable to signature forgery through altered presignatures
High
Network
Low
None
None
ImpactThis attack is against presignatures used in very specific context:
Patches
WorkaroundsUsers can continue using un-patched versions of library as long as they don't use presignatures in said scenarios where it weakens system security. To be sure, migrate to patched version that excludes presignatures from being used in such scenarios. ReferencesRead this blog post to learn more. References
Updated Nov 27, 2025 · Source: OSV.dev
CVE-2025-66016
GHSA-m95p-425x-x889
RUSTSEC-2025-0129
RUSTSEC-2025-0130
Nov 25, 2025
cggmp21 has a missing check in the ZK proof used in CGGMP21
Critical
Network
Low
None
None
Impactcggmp21 concerns a missing check in the ZK proof that enables an attack in which a single malicious signer can reconstruct full private key. Patches
WorkaroundsUpdate to However, for full mitigation, users will need to upgrade to ResourcesRead this blog post to learn more. Fixed in
0.6.3
References
Updated Nov 27, 2025 · Source: OSV.dev |
0.6.1
unknown
Dependencies (21)
+ 13 more |
|
0.6.0
unknown
2 CVEs
CVE-2025-66017
GHSA-8frv-q972-9rq5
RUSTSEC-2025-0127
RUSTSEC-2025-0128
Nov 25, 2025
cggmp24 and cggmp21 are vulnerable to signature forgery through altered presignatures
High
Network
Low
None
None
ImpactThis attack is against presignatures used in very specific context:
Patches
WorkaroundsUsers can continue using un-patched versions of library as long as they don't use presignatures in said scenarios where it weakens system security. To be sure, migrate to patched version that excludes presignatures from being used in such scenarios. ReferencesRead this blog post to learn more. References
Updated Nov 27, 2025 · Source: OSV.dev
CVE-2025-66016
GHSA-m95p-425x-x889
RUSTSEC-2025-0129
RUSTSEC-2025-0130
Nov 25, 2025
cggmp21 has a missing check in the ZK proof used in CGGMP21
Critical
Network
Low
None
None
Impactcggmp21 concerns a missing check in the ZK proof that enables an attack in which a single malicious signer can reconstruct full private key. Patches
WorkaroundsUpdate to However, for full mitigation, users will need to upgrade to ResourcesRead this blog post to learn more. Fixed in
0.6.3
References
Updated Nov 27, 2025 · Source: OSV.dev |
0.6.0
unknown
Dependencies (21)
+ 13 more |
|
0.5.2
unknown
2 CVEs
CVE-2025-66017
GHSA-8frv-q972-9rq5
RUSTSEC-2025-0127
RUSTSEC-2025-0128
Nov 25, 2025
cggmp24 and cggmp21 are vulnerable to signature forgery through altered presignatures
High
Network
Low
None
None
ImpactThis attack is against presignatures used in very specific context:
Patches
WorkaroundsUsers can continue using un-patched versions of library as long as they don't use presignatures in said scenarios where it weakens system security. To be sure, migrate to patched version that excludes presignatures from being used in such scenarios. ReferencesRead this blog post to learn more. References
Updated Nov 27, 2025 · Source: OSV.dev
CVE-2025-66016
GHSA-m95p-425x-x889
RUSTSEC-2025-0129
RUSTSEC-2025-0130
Nov 25, 2025
cggmp21 has a missing check in the ZK proof used in CGGMP21
Critical
Network
Low
None
None
Impactcggmp21 concerns a missing check in the ZK proof that enables an attack in which a single malicious signer can reconstruct full private key. Patches
WorkaroundsUpdate to However, for full mitigation, users will need to upgrade to ResourcesRead this blog post to learn more. Fixed in
0.6.3
References
Updated Nov 27, 2025 · Source: OSV.dev |
0.5.2
unknown
Dependencies (21)
+ 13 more |
|
0.5.1
unknown
2 CVEs
CVE-2025-66017
GHSA-8frv-q972-9rq5
RUSTSEC-2025-0127
RUSTSEC-2025-0128
Nov 25, 2025
cggmp24 and cggmp21 are vulnerable to signature forgery through altered presignatures
High
Network
Low
None
None
ImpactThis attack is against presignatures used in very specific context:
Patches
WorkaroundsUsers can continue using un-patched versions of library as long as they don't use presignatures in said scenarios where it weakens system security. To be sure, migrate to patched version that excludes presignatures from being used in such scenarios. ReferencesRead this blog post to learn more. References
Updated Nov 27, 2025 · Source: OSV.dev
CVE-2025-66016
GHSA-m95p-425x-x889
RUSTSEC-2025-0129
RUSTSEC-2025-0130
Nov 25, 2025
cggmp21 has a missing check in the ZK proof used in CGGMP21
Critical
Network
Low
None
None
Impactcggmp21 concerns a missing check in the ZK proof that enables an attack in which a single malicious signer can reconstruct full private key. Patches
WorkaroundsUpdate to However, for full mitigation, users will need to upgrade to ResourcesRead this blog post to learn more. Fixed in
0.6.3
References
Updated Nov 27, 2025 · Source: OSV.dev |
0.5.1
unknown
Dependencies (21)
+ 13 more |
|
0.5.0
unknown
2 CVEs
CVE-2025-66017
GHSA-8frv-q972-9rq5
RUSTSEC-2025-0127
RUSTSEC-2025-0128
Nov 25, 2025
cggmp24 and cggmp21 are vulnerable to signature forgery through altered presignatures
High
Network
Low
None
None
ImpactThis attack is against presignatures used in very specific context:
Patches
WorkaroundsUsers can continue using un-patched versions of library as long as they don't use presignatures in said scenarios where it weakens system security. To be sure, migrate to patched version that excludes presignatures from being used in such scenarios. ReferencesRead this blog post to learn more. References
Updated Nov 27, 2025 · Source: OSV.dev
CVE-2025-66016
GHSA-m95p-425x-x889
RUSTSEC-2025-0129
RUSTSEC-2025-0130
Nov 25, 2025
cggmp21 has a missing check in the ZK proof used in CGGMP21
Critical
Network
Low
None
None
Impactcggmp21 concerns a missing check in the ZK proof that enables an attack in which a single malicious signer can reconstruct full private key. Patches
WorkaroundsUpdate to However, for full mitigation, users will need to upgrade to ResourcesRead this blog post to learn more. Fixed in
0.6.3
References
Updated Nov 27, 2025 · Source: OSV.dev |
0.5.0
unknown
Dependencies (21)
+ 13 more |
|
0.4.2
unknown
2 CVEs
CVE-2025-66017
GHSA-8frv-q972-9rq5
RUSTSEC-2025-0127
RUSTSEC-2025-0128
Nov 25, 2025
cggmp24 and cggmp21 are vulnerable to signature forgery through altered presignatures
High
Network
Low
None
None
ImpactThis attack is against presignatures used in very specific context:
Patches
WorkaroundsUsers can continue using un-patched versions of library as long as they don't use presignatures in said scenarios where it weakens system security. To be sure, migrate to patched version that excludes presignatures from being used in such scenarios. ReferencesRead this blog post to learn more. References
Updated Nov 27, 2025 · Source: OSV.dev
CVE-2025-66016
GHSA-m95p-425x-x889
RUSTSEC-2025-0129
RUSTSEC-2025-0130
Nov 25, 2025
cggmp21 has a missing check in the ZK proof used in CGGMP21
Critical
Network
Low
None
None
Impactcggmp21 concerns a missing check in the ZK proof that enables an attack in which a single malicious signer can reconstruct full private key. Patches
WorkaroundsUpdate to However, for full mitigation, users will need to upgrade to ResourcesRead this blog post to learn more. Fixed in
0.6.3
References
Updated Nov 27, 2025 · Source: OSV.dev |
0.4.2
unknown
Dependencies (21)
+ 13 more |
|
0.4.1
unknown
2 CVEs
CVE-2025-66017
GHSA-8frv-q972-9rq5
RUSTSEC-2025-0127
RUSTSEC-2025-0128
Nov 25, 2025
cggmp24 and cggmp21 are vulnerable to signature forgery through altered presignatures
High
Network
Low
None
None
ImpactThis attack is against presignatures used in very specific context:
Patches
WorkaroundsUsers can continue using un-patched versions of library as long as they don't use presignatures in said scenarios where it weakens system security. To be sure, migrate to patched version that excludes presignatures from being used in such scenarios. ReferencesRead this blog post to learn more. References
Updated Nov 27, 2025 · Source: OSV.dev
CVE-2025-66016
GHSA-m95p-425x-x889
RUSTSEC-2025-0129
RUSTSEC-2025-0130
Nov 25, 2025
cggmp21 has a missing check in the ZK proof used in CGGMP21
Critical
Network
Low
None
None
Impactcggmp21 concerns a missing check in the ZK proof that enables an attack in which a single malicious signer can reconstruct full private key. Patches
WorkaroundsUpdate to However, for full mitigation, users will need to upgrade to ResourcesRead this blog post to learn more. Fixed in
0.6.3
References
Updated Nov 27, 2025 · Source: OSV.dev |
0.4.1
unknown
Dependencies (21)
+ 13 more |
|
0.4.0
unknown
2 CVEs
CVE-2025-66017
GHSA-8frv-q972-9rq5
RUSTSEC-2025-0127
RUSTSEC-2025-0128
Nov 25, 2025
cggmp24 and cggmp21 are vulnerable to signature forgery through altered presignatures
High
Network
Low
None
None
ImpactThis attack is against presignatures used in very specific context:
Patches
WorkaroundsUsers can continue using un-patched versions of library as long as they don't use presignatures in said scenarios where it weakens system security. To be sure, migrate to patched version that excludes presignatures from being used in such scenarios. ReferencesRead this blog post to learn more. References
Updated Nov 27, 2025 · Source: OSV.dev
CVE-2025-66016
GHSA-m95p-425x-x889
RUSTSEC-2025-0129
RUSTSEC-2025-0130
Nov 25, 2025
cggmp21 has a missing check in the ZK proof used in CGGMP21
Critical
Network
Low
None
None
Impactcggmp21 concerns a missing check in the ZK proof that enables an attack in which a single malicious signer can reconstruct full private key. Patches
WorkaroundsUpdate to However, for full mitigation, users will need to upgrade to ResourcesRead this blog post to learn more. Fixed in
0.6.3
References
Updated Nov 27, 2025 · Source: OSV.dev |
0.4.0
unknown
Dependencies (21)
+ 13 more |
|
0.2.1
unknown
3 CVEs
CVE-2025-66017
GHSA-8frv-q972-9rq5
RUSTSEC-2025-0127
RUSTSEC-2025-0128
Nov 25, 2025
cggmp24 and cggmp21 are vulnerable to signature forgery through altered presignatures
High
Network
Low
None
None
ImpactThis attack is against presignatures used in very specific context:
Patches
WorkaroundsUsers can continue using un-patched versions of library as long as they don't use presignatures in said scenarios where it weakens system security. To be sure, migrate to patched version that excludes presignatures from being used in such scenarios. ReferencesRead this blog post to learn more. References
Updated Nov 27, 2025 · Source: OSV.dev
CVE-2025-66016
GHSA-m95p-425x-x889
RUSTSEC-2025-0129
RUSTSEC-2025-0130
Nov 25, 2025
cggmp21 has a missing check in the ZK proof used in CGGMP21
Critical
Network
Low
None
None
Impactcggmp21 concerns a missing check in the ZK proof that enables an attack in which a single malicious signer can reconstruct full private key. Patches
WorkaroundsUpdate to However, for full mitigation, users will need to upgrade to ResourcesRead this blog post to learn more. Fixed in
0.6.3
References
Updated Nov 27, 2025 · Source: OSV.dev
GHSA-rm66-9gh4-4gp8
RUSTSEC-2024-0393
Nov 12, 2024
cggmp21 vulnerable to ambiguous challenge derivation
Low
Network
Low
None
None
Challenge derivation in non-interactive ZK proofs was ambiguous and that could lead to security vulnerability (however, it's unknown if it could be exploited). Fixed in
0.4.0
References Updated Oct 28, 2025 · Source: OSV.dev |
0.2.1
unknown
Dependencies (22)
+ 14 more |
|
0.2.0
unknown
3 CVEs
CVE-2025-66017
GHSA-8frv-q972-9rq5
RUSTSEC-2025-0127
RUSTSEC-2025-0128
Nov 25, 2025
cggmp24 and cggmp21 are vulnerable to signature forgery through altered presignatures
High
Network
Low
None
None
ImpactThis attack is against presignatures used in very specific context:
Patches
WorkaroundsUsers can continue using un-patched versions of library as long as they don't use presignatures in said scenarios where it weakens system security. To be sure, migrate to patched version that excludes presignatures from being used in such scenarios. ReferencesRead this blog post to learn more. References
Updated Nov 27, 2025 · Source: OSV.dev
CVE-2025-66016
GHSA-m95p-425x-x889
RUSTSEC-2025-0129
RUSTSEC-2025-0130
Nov 25, 2025
cggmp21 has a missing check in the ZK proof used in CGGMP21
Critical
Network
Low
None
None
Impactcggmp21 concerns a missing check in the ZK proof that enables an attack in which a single malicious signer can reconstruct full private key. Patches
WorkaroundsUpdate to However, for full mitigation, users will need to upgrade to ResourcesRead this blog post to learn more. Fixed in
0.6.3
References
Updated Nov 27, 2025 · Source: OSV.dev
GHSA-rm66-9gh4-4gp8
RUSTSEC-2024-0393
Nov 12, 2024
cggmp21 vulnerable to ambiguous challenge derivation
Low
Network
Low
None
None
Challenge derivation in non-interactive ZK proofs was ambiguous and that could lead to security vulnerability (however, it's unknown if it could be exploited). Fixed in
0.4.0
References Updated Oct 28, 2025 · Source: OSV.dev |
0.2.0
unknown
Dependencies (22)
+ 14 more |
|
0.1.1
unknown
3 CVEs
CVE-2025-66017
GHSA-8frv-q972-9rq5
RUSTSEC-2025-0127
RUSTSEC-2025-0128
Nov 25, 2025
cggmp24 and cggmp21 are vulnerable to signature forgery through altered presignatures
High
Network
Low
None
None
ImpactThis attack is against presignatures used in very specific context:
Patches
WorkaroundsUsers can continue using un-patched versions of library as long as they don't use presignatures in said scenarios where it weakens system security. To be sure, migrate to patched version that excludes presignatures from being used in such scenarios. ReferencesRead this blog post to learn more. References
Updated Nov 27, 2025 · Source: OSV.dev
CVE-2025-66016
GHSA-m95p-425x-x889
RUSTSEC-2025-0129
RUSTSEC-2025-0130
Nov 25, 2025
cggmp21 has a missing check in the ZK proof used in CGGMP21
Critical
Network
Low
None
None
Impactcggmp21 concerns a missing check in the ZK proof that enables an attack in which a single malicious signer can reconstruct full private key. Patches
WorkaroundsUpdate to However, for full mitigation, users will need to upgrade to ResourcesRead this blog post to learn more. Fixed in
0.6.3
References
Updated Nov 27, 2025 · Source: OSV.dev
GHSA-rm66-9gh4-4gp8
RUSTSEC-2024-0393
Nov 12, 2024
cggmp21 vulnerable to ambiguous challenge derivation
Low
Network
Low
None
None
Challenge derivation in non-interactive ZK proofs was ambiguous and that could lead to security vulnerability (however, it's unknown if it could be exploited). Fixed in
0.4.0
References Updated Oct 28, 2025 · Source: OSV.dev |
0.1.1
unknown
Dependencies (19)
+ 11 more |
|
0.1.0
unknown
3 CVEs
CVE-2025-66017
GHSA-8frv-q972-9rq5
RUSTSEC-2025-0127
RUSTSEC-2025-0128
Nov 25, 2025
cggmp24 and cggmp21 are vulnerable to signature forgery through altered presignatures
High
Network
Low
None
None
ImpactThis attack is against presignatures used in very specific context:
Patches
WorkaroundsUsers can continue using un-patched versions of library as long as they don't use presignatures in said scenarios where it weakens system security. To be sure, migrate to patched version that excludes presignatures from being used in such scenarios. ReferencesRead this blog post to learn more. References
Updated Nov 27, 2025 · Source: OSV.dev
CVE-2025-66016
GHSA-m95p-425x-x889
RUSTSEC-2025-0129
RUSTSEC-2025-0130
Nov 25, 2025
cggmp21 has a missing check in the ZK proof used in CGGMP21
Critical
Network
Low
None
None
Impactcggmp21 concerns a missing check in the ZK proof that enables an attack in which a single malicious signer can reconstruct full private key. Patches
WorkaroundsUpdate to However, for full mitigation, users will need to upgrade to ResourcesRead this blog post to learn more. Fixed in
0.6.3
References
Updated Nov 27, 2025 · Source: OSV.dev
GHSA-rm66-9gh4-4gp8
RUSTSEC-2024-0393
Nov 12, 2024
cggmp21 vulnerable to ambiguous challenge derivation
Low
Network
Low
None
None
Challenge derivation in non-interactive ZK proofs was ambiguous and that could lead to security vulnerability (however, it's unknown if it could be exploited). Fixed in
0.4.0
References Updated Oct 28, 2025 · Source: OSV.dev |
0.1.0
unknown
Dependencies (19)
+ 11 more |
|
0.0.0
unknown
3 CVEs
CVE-2025-66017
GHSA-8frv-q972-9rq5
RUSTSEC-2025-0127
RUSTSEC-2025-0128
Nov 25, 2025
cggmp24 and cggmp21 are vulnerable to signature forgery through altered presignatures
High
Network
Low
None
None
ImpactThis attack is against presignatures used in very specific context:
Patches
WorkaroundsUsers can continue using un-patched versions of library as long as they don't use presignatures in said scenarios where it weakens system security. To be sure, migrate to patched version that excludes presignatures from being used in such scenarios. ReferencesRead this blog post to learn more. References
Updated Nov 27, 2025 · Source: OSV.dev
CVE-2025-66016
GHSA-m95p-425x-x889
RUSTSEC-2025-0129
RUSTSEC-2025-0130
Nov 25, 2025
cggmp21 has a missing check in the ZK proof used in CGGMP21
Critical
Network
Low
None
None
Impactcggmp21 concerns a missing check in the ZK proof that enables an attack in which a single malicious signer can reconstruct full private key. Patches
WorkaroundsUpdate to However, for full mitigation, users will need to upgrade to ResourcesRead this blog post to learn more. Fixed in
0.6.3
References
Updated Nov 27, 2025 · Source: OSV.dev
GHSA-rm66-9gh4-4gp8
RUSTSEC-2024-0393
Nov 12, 2024
cggmp21 vulnerable to ambiguous challenge derivation
Low
Network
Low
None
None
Challenge derivation in non-interactive ZK proofs was ambiguous and that could lead to security vulnerability (however, it's unknown if it could be exploited). Fixed in
0.4.0
References Updated Oct 28, 2025 · Source: OSV.dev |
0.0.0
unknown
|