libsecp256k1
Activity
- Latest release
- 1y ago
- Total releases
- 29
- Cadence
- ~17 days
- Last 12 months
- 0
Details
- License
- Apache-2.0
- First release
- Nov 10, 2017
| Version | Released | |
|---|---|---|
0.7.2
unknown
1 CVE
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev |
0.7.2
unknown
Dependencies (18)
+ 10 more |
|
0.7.1
unknown
1 CVE
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev |
0.7.1
unknown
Dependencies (18)
+ 10 more |
|
0.7.0
unknown
1 CVE
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev |
0.7.0
unknown
Dependencies (16)
+ 8 more |
|
0.6.0
unknown
1 CVE
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev |
0.6.0
unknown
Dependencies (16)
+ 8 more |
|
0.5.0
unknown
1 CVE
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev |
0.5.0
unknown
Dependencies (15)
+ 7 more |
|
0.3.5
unknown
2 CVEs
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2021-38195
GHSA-g4vj-x7v9-h82m
RUSTSEC-2021-0076
Aug 25, 2021
Overflow in libsecp256k1
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow. Fixed in
0.5.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.5
unknown
Dependencies (12)
+ 4 more |
|
0.3.4
unknown
2 CVEs
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2021-38195
GHSA-g4vj-x7v9-h82m
RUSTSEC-2021-0076
Aug 25, 2021
Overflow in libsecp256k1
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow. Fixed in
0.5.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.4
unknown
Dependencies (11)
+ 3 more |
|
0.3.3
unknown
2 CVEs
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2021-38195
GHSA-g4vj-x7v9-h82m
RUSTSEC-2021-0076
Aug 25, 2021
Overflow in libsecp256k1
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow. Fixed in
0.5.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.3
unknown
Dependencies (11)
+ 3 more |
|
0.3.2
unknown
2 CVEs
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2021-38195
GHSA-g4vj-x7v9-h82m
RUSTSEC-2021-0076
Aug 25, 2021
Overflow in libsecp256k1
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow. Fixed in
0.5.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.2
unknown
Dependencies (10)
+ 2 more |
|
0.3.1
unknown
yanked
2 CVEs
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2021-38195
GHSA-g4vj-x7v9-h82m
RUSTSEC-2021-0076
Aug 25, 2021
Overflow in libsecp256k1
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow. Fixed in
0.5.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.1
unknown
yanked
Dependencies (10)
+ 2 more |
|
0.3.0
unknown
yanked
3 CVEs
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2021-38195
GHSA-g4vj-x7v9-h82m
RUSTSEC-2021-0076
Aug 25, 2021
Overflow in libsecp256k1
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow. Fixed in
0.5.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-25003
GHSA-hrjm-c879-pp86
RUSTSEC-2019-0027
Aug 25, 2021
libsecp256k1 contains side-channel timing attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Versions of libsecp256k1 prior to 0.3.1 did not execute Fixed in
0.3.1
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.0
unknown
yanked
Dependencies (9)
+ 1 more |
|
0.2.2
unknown
3 CVEs
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2021-38195
GHSA-g4vj-x7v9-h82m
RUSTSEC-2021-0076
Aug 25, 2021
Overflow in libsecp256k1
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow. Fixed in
0.5.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-25003
GHSA-hrjm-c879-pp86
RUSTSEC-2019-0027
Aug 25, 2021
libsecp256k1 contains side-channel timing attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Versions of libsecp256k1 prior to 0.3.1 did not execute Fixed in
0.3.1
References Updated Nov 08, 2023 · Source: OSV.dev |
0.2.2
unknown
Dependencies (9)
+ 1 more |
|
0.2.1
unknown
3 CVEs
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2021-38195
GHSA-g4vj-x7v9-h82m
RUSTSEC-2021-0076
Aug 25, 2021
Overflow in libsecp256k1
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow. Fixed in
0.5.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-25003
GHSA-hrjm-c879-pp86
RUSTSEC-2019-0027
Aug 25, 2021
libsecp256k1 contains side-channel timing attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Versions of libsecp256k1 prior to 0.3.1 did not execute Fixed in
0.3.1
References Updated Nov 08, 2023 · Source: OSV.dev |
0.2.1
unknown
Dependencies (9)
+ 1 more |
|
0.2.0
unknown
3 CVEs
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2021-38195
GHSA-g4vj-x7v9-h82m
RUSTSEC-2021-0076
Aug 25, 2021
Overflow in libsecp256k1
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow. Fixed in
0.5.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-25003
GHSA-hrjm-c879-pp86
RUSTSEC-2019-0027
Aug 25, 2021
libsecp256k1 contains side-channel timing attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Versions of libsecp256k1 prior to 0.3.1 did not execute Fixed in
0.3.1
References Updated Nov 08, 2023 · Source: OSV.dev |
0.2.0
unknown
Dependencies (9)
+ 1 more |
|
0.1.15
unknown
3 CVEs
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2021-38195
GHSA-g4vj-x7v9-h82m
RUSTSEC-2021-0076
Aug 25, 2021
Overflow in libsecp256k1
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow. Fixed in
0.5.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-25003
GHSA-hrjm-c879-pp86
RUSTSEC-2019-0027
Aug 25, 2021
libsecp256k1 contains side-channel timing attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Versions of libsecp256k1 prior to 0.3.1 did not execute Fixed in
0.3.1
References Updated Nov 08, 2023 · Source: OSV.dev |
0.1.15
unknown
Dependencies (8)
|
|
0.1.14
unknown
3 CVEs
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2021-38195
GHSA-g4vj-x7v9-h82m
RUSTSEC-2021-0076
Aug 25, 2021
Overflow in libsecp256k1
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow. Fixed in
0.5.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-25003
GHSA-hrjm-c879-pp86
RUSTSEC-2019-0027
Aug 25, 2021
libsecp256k1 contains side-channel timing attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Versions of libsecp256k1 prior to 0.3.1 did not execute Fixed in
0.3.1
References Updated Nov 08, 2023 · Source: OSV.dev |
0.1.14
unknown
Dependencies (9)
+ 1 more |
|
0.1.13
unknown
3 CVEs
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2021-38195
GHSA-g4vj-x7v9-h82m
RUSTSEC-2021-0076
Aug 25, 2021
Overflow in libsecp256k1
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow. Fixed in
0.5.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-25003
GHSA-hrjm-c879-pp86
RUSTSEC-2019-0027
Aug 25, 2021
libsecp256k1 contains side-channel timing attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Versions of libsecp256k1 prior to 0.3.1 did not execute Fixed in
0.3.1
References Updated Nov 08, 2023 · Source: OSV.dev |
0.1.13
unknown
Dependencies (8)
|
|
0.1.12
unknown
3 CVEs
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2021-38195
GHSA-g4vj-x7v9-h82m
RUSTSEC-2021-0076
Aug 25, 2021
Overflow in libsecp256k1
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow. Fixed in
0.5.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-25003
GHSA-hrjm-c879-pp86
RUSTSEC-2019-0027
Aug 25, 2021
libsecp256k1 contains side-channel timing attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Versions of libsecp256k1 prior to 0.3.1 did not execute Fixed in
0.3.1
References Updated Nov 08, 2023 · Source: OSV.dev |
0.1.12
unknown
Dependencies (7)
|
|
0.1.11
unknown
3 CVEs
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2021-38195
GHSA-g4vj-x7v9-h82m
RUSTSEC-2021-0076
Aug 25, 2021
Overflow in libsecp256k1
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow. Fixed in
0.5.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-25003
GHSA-hrjm-c879-pp86
RUSTSEC-2019-0027
Aug 25, 2021
libsecp256k1 contains side-channel timing attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Versions of libsecp256k1 prior to 0.3.1 did not execute Fixed in
0.3.1
References Updated Nov 08, 2023 · Source: OSV.dev |
0.1.11
unknown
Dependencies (6)
|
|
0.1.10
unknown
3 CVEs
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2021-38195
GHSA-g4vj-x7v9-h82m
RUSTSEC-2021-0076
Aug 25, 2021
Overflow in libsecp256k1
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow. Fixed in
0.5.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-25003
GHSA-hrjm-c879-pp86
RUSTSEC-2019-0027
Aug 25, 2021
libsecp256k1 contains side-channel timing attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Versions of libsecp256k1 prior to 0.3.1 did not execute Fixed in
0.3.1
References Updated Nov 08, 2023 · Source: OSV.dev |
0.1.10
unknown
Dependencies (6)
|
|
0.1.9
unknown
3 CVEs
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2021-38195
GHSA-g4vj-x7v9-h82m
RUSTSEC-2021-0076
Aug 25, 2021
Overflow in libsecp256k1
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow. Fixed in
0.5.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-25003
GHSA-hrjm-c879-pp86
RUSTSEC-2019-0027
Aug 25, 2021
libsecp256k1 contains side-channel timing attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Versions of libsecp256k1 prior to 0.3.1 did not execute Fixed in
0.3.1
References Updated Nov 08, 2023 · Source: OSV.dev |
0.1.9
unknown
Dependencies (6)
|
|
0.1.8
unknown
3 CVEs
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2021-38195
GHSA-g4vj-x7v9-h82m
RUSTSEC-2021-0076
Aug 25, 2021
Overflow in libsecp256k1
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow. Fixed in
0.5.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-25003
GHSA-hrjm-c879-pp86
RUSTSEC-2019-0027
Aug 25, 2021
libsecp256k1 contains side-channel timing attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Versions of libsecp256k1 prior to 0.3.1 did not execute Fixed in
0.3.1
References Updated Nov 08, 2023 · Source: OSV.dev |
0.1.8
unknown
Dependencies (6)
|
|
0.1.7
unknown
3 CVEs
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2021-38195
GHSA-g4vj-x7v9-h82m
RUSTSEC-2021-0076
Aug 25, 2021
Overflow in libsecp256k1
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow. Fixed in
0.5.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-25003
GHSA-hrjm-c879-pp86
RUSTSEC-2019-0027
Aug 25, 2021
libsecp256k1 contains side-channel timing attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Versions of libsecp256k1 prior to 0.3.1 did not execute Fixed in
0.3.1
References Updated Nov 08, 2023 · Source: OSV.dev |
0.1.7
unknown
Dependencies (6)
|
|
0.1.6
unknown
3 CVEs
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2021-38195
GHSA-g4vj-x7v9-h82m
RUSTSEC-2021-0076
Aug 25, 2021
Overflow in libsecp256k1
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow. Fixed in
0.5.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-25003
GHSA-hrjm-c879-pp86
RUSTSEC-2019-0027
Aug 25, 2021
libsecp256k1 contains side-channel timing attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Versions of libsecp256k1 prior to 0.3.1 did not execute Fixed in
0.3.1
References Updated Nov 08, 2023 · Source: OSV.dev |
0.1.6
unknown
Dependencies (6)
|
|
0.1.5
unknown
3 CVEs
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2021-38195
GHSA-g4vj-x7v9-h82m
RUSTSEC-2021-0076
Aug 25, 2021
Overflow in libsecp256k1
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow. Fixed in
0.5.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-25003
GHSA-hrjm-c879-pp86
RUSTSEC-2019-0027
Aug 25, 2021
libsecp256k1 contains side-channel timing attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Versions of libsecp256k1 prior to 0.3.1 did not execute Fixed in
0.3.1
References Updated Nov 08, 2023 · Source: OSV.dev |
0.1.5
unknown
Dependencies (6)
|
|
0.1.4
unknown
3 CVEs
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2021-38195
GHSA-g4vj-x7v9-h82m
RUSTSEC-2021-0076
Aug 25, 2021
Overflow in libsecp256k1
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow. Fixed in
0.5.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-25003
GHSA-hrjm-c879-pp86
RUSTSEC-2019-0027
Aug 25, 2021
libsecp256k1 contains side-channel timing attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Versions of libsecp256k1 prior to 0.3.1 did not execute Fixed in
0.3.1
References Updated Nov 08, 2023 · Source: OSV.dev |
0.1.4
unknown
Dependencies (6)
|
|
0.1.3
unknown
3 CVEs
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2021-38195
GHSA-g4vj-x7v9-h82m
RUSTSEC-2021-0076
Aug 25, 2021
Overflow in libsecp256k1
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow. Fixed in
0.5.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-25003
GHSA-hrjm-c879-pp86
RUSTSEC-2019-0027
Aug 25, 2021
libsecp256k1 contains side-channel timing attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Versions of libsecp256k1 prior to 0.3.1 did not execute Fixed in
0.3.1
References Updated Nov 08, 2023 · Source: OSV.dev |
0.1.3
unknown
Dependencies (3)
|
|
0.1.2
unknown
3 CVEs
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2021-38195
GHSA-g4vj-x7v9-h82m
RUSTSEC-2021-0076
Aug 25, 2021
Overflow in libsecp256k1
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow. Fixed in
0.5.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-25003
GHSA-hrjm-c879-pp86
RUSTSEC-2019-0027
Aug 25, 2021
libsecp256k1 contains side-channel timing attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Versions of libsecp256k1 prior to 0.3.1 did not execute Fixed in
0.3.1
References Updated Nov 08, 2023 · Source: OSV.dev |
0.1.2
unknown
Dependencies (3)
|
|
0.1.0
unknown
3 CVEs
RUSTSEC-2025-0161
Jan 14, 2025
libsecp256k1 is unmaintained The maintainers recommend using k256 instead. References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2021-38195
GHSA-g4vj-x7v9-h82m
RUSTSEC-2021-0076
Aug 25, 2021
Overflow in libsecp256k1
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow. Fixed in
0.5.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-25003
GHSA-hrjm-c879-pp86
RUSTSEC-2019-0027
Aug 25, 2021
libsecp256k1 contains side-channel timing attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Versions of libsecp256k1 prior to 0.3.1 did not execute Fixed in
0.3.1
References Updated Nov 08, 2023 · Source: OSV.dev |
0.1.0
unknown
|