cggmp24
Activity
- Latest release
- 9mo ago
- Total releases
- 4
- Cadence
- ~3 months
- Last 12 months
- 2
Details
- License
- MIT OR Apache-2.0
- First release
- Dec 06, 2024
| Version | Released | |
|---|---|---|
0.7.0-alpha.3
unknown
|
0.7.0-alpha.3
unknown
Dependencies (21)
+ 13 more |
|
0.7.0-alpha.2
unknown
|
0.7.0-alpha.2
unknown
Dependencies (21)
+ 13 more |
|
0.7.0-alpha.1
unknown
2 CVEs
CVE-2025-66017
GHSA-8frv-q972-9rq5
RUSTSEC-2025-0127
RUSTSEC-2025-0128
Nov 25, 2025
cggmp24 and cggmp21 are vulnerable to signature forgery through altered presignatures
High
Network
Low
None
None
ImpactThis attack is against presignatures used in very specific context:
Patches
WorkaroundsUsers can continue using un-patched versions of library as long as they don't use presignatures in said scenarios where it weakens system security. To be sure, migrate to patched version that excludes presignatures from being used in such scenarios. ReferencesRead this blog post to learn more. Fixed in
0.7.0-alpha.2
References
Updated Nov 27, 2025 · Source: OSV.dev
CVE-2025-66016
GHSA-m95p-425x-x889
RUSTSEC-2025-0129
RUSTSEC-2025-0130
Nov 25, 2025
cggmp21 has a missing check in the ZK proof used in CGGMP21
Critical
Network
Low
None
None
Impactcggmp21 concerns a missing check in the ZK proof that enables an attack in which a single malicious signer can reconstruct full private key. Patches
WorkaroundsUpdate to However, for full mitigation, users will need to upgrade to ResourcesRead this blog post to learn more. Fixed in
0.7.0-alpha.2
References
Updated Nov 27, 2025 · Source: OSV.dev |
0.7.0-alpha.1
unknown
Dependencies (21)
+ 13 more |
|
0.1.0
unknown
2 CVEs
CVE-2025-66017
GHSA-8frv-q972-9rq5
RUSTSEC-2025-0127
RUSTSEC-2025-0128
Nov 25, 2025
cggmp24 and cggmp21 are vulnerable to signature forgery through altered presignatures
High
Network
Low
None
None
ImpactThis attack is against presignatures used in very specific context:
Patches
WorkaroundsUsers can continue using un-patched versions of library as long as they don't use presignatures in said scenarios where it weakens system security. To be sure, migrate to patched version that excludes presignatures from being used in such scenarios. ReferencesRead this blog post to learn more. Fixed in
0.7.0-alpha.2
References
Updated Nov 27, 2025 · Source: OSV.dev
CVE-2025-66016
GHSA-m95p-425x-x889
RUSTSEC-2025-0129
RUSTSEC-2025-0130
Nov 25, 2025
cggmp21 has a missing check in the ZK proof used in CGGMP21
Critical
Network
Low
None
None
Impactcggmp21 concerns a missing check in the ZK proof that enables an attack in which a single malicious signer can reconstruct full private key. Patches
WorkaroundsUpdate to However, for full mitigation, users will need to upgrade to ResourcesRead this blog post to learn more. Fixed in
0.7.0-alpha.2
References
Updated Nov 27, 2025 · Source: OSV.dev |
0.1.0
unknown
|