github.com/consensys/gnark
gnark is a fast zk-SNARK library that offers a high-level API to design circuits. The library is open source and developed under the Apache 2.0 license
Activity
- Latest release
- 2w ago
- Total releases
- 41
- Cadence
- ~28 days
- Last 12 months
- 5
Reach
- Stars
- 1.7k
Details
- First release
- Mar 06, 2020
| Version | Released | |
|---|---|---|
v0.16.3
patch
|
v0.16.3
patch
Dependencies (16)
+ 8 more |
|
v0.16.2
patch
|
v0.16.2
patch
Dependencies (16)
+ 8 more |
|
v0.16.1
patch
|
v0.16.1
patch
Dependencies (16)
+ 8 more |
|
v0.16.0
minor
|
v0.16.0
minor
Dependencies (16)
+ 8 more |
|
v0.15.0
minor
|
v0.15.0
minor
Dependencies (16)
+ 8 more |
|
v0.14.0
minor
|
v0.14.0
minor
Dependencies (17)
+ 9 more |
|
v0.13.0
minor
1 CVE
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.13.0
minor
Dependencies (17)
+ 9 more |
|
v0.12.0
minor
2 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.12.0
minor
Dependencies (17)
+ 9 more |
|
v0.11.0
minor
3 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev |
v0.11.0
minor
Dependencies (17)
+ 9 more |
|
v0.10.0
minor
5 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev |
v0.10.0
minor
Dependencies (16)
+ 8 more |
|
v0.9.1
patch
6 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev |
v0.9.1
patch
Dependencies (13)
+ 5 more |
|
v0.9.0
minor
7 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev |
v0.9.0
minor
Dependencies (13)
+ 5 more |
|
v0.9.0-alpha
pre
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.9.0-alpha
pre
Dependencies (13)
+ 5 more |
|
v0.8.1
patch
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.8.1
patch
Dependencies (10)
+ 2 more |
|
v0.8.0
minor
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.8.0
minor
Dependencies (10)
+ 2 more |
|
v0.7.1
patch
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.7.1
patch
Dependencies (6)
|
|
v0.6.5
patch
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.6.5
patch
Dependencies (5)
|
|
v0.7.0
minor
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.7.0
minor
Dependencies (6)
|
|
v0.6.4
patch
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.6.4
patch
Dependencies (5)
|
|
v0.6.3
patch
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.6.3
patch
Dependencies (5)
|
|
v0.6.2
patch
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.6.2
patch
Dependencies (5)
|
|
v0.6.1
patch
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.6.1
patch
Dependencies (5)
|
|
v0.6.0
minor
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.6.0
minor
Dependencies (5)
|
|
v0.5.1-hotfixes
pre
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.5.1-hotfixes
pre
Dependencies (5)
|
|
v0.5.2
patch
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.5.2
patch
Dependencies (5)
|
|
v0.5.1
patch
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.5.1
patch
Dependencies (5)
|
|
v0.5.0
minor
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.5.0
minor
Dependencies (5)
|
|
v0.4.0
minor
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.4.0
minor
Dependencies (9)
+ 1 more |
|
v0.3.8
patch
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.3.8
patch
Dependencies (6)
|
|
v0.3.7
patch
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.3.7
patch
Dependencies (6)
|
|
v0.3.6
patch
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.3.6
patch
Dependencies (6)
|
|
v0.3.5
patch
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.3.5
patch
Dependencies (7)
|
|
v0.3.4
patch
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.3.4
patch
Dependencies (7)
|
|
v0.3.3
patch
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.3.3
patch
Dependencies (7)
|
|
v0.3.2
patch
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.3.2
patch
Dependencies (7)
|
|
v0.3.1
patch
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.3.1
patch
Dependencies (7)
|
|
v0.3.0
initial
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.3.0
initial
Dependencies (7)
|
|
v0.3.0-alpha
pre
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.3.0-alpha
pre
Dependencies (7)
|
|
v0.2.1-alpha
pre
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.2.1-alpha
pre
Dependencies (7)
|
|
v0.2.0-alpha
pre
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.2.0-alpha
pre
Dependencies (7)
|
|
v0.1.0-alpha
pre
8 CVEs
CVE-2025-58157
GO-2025-3929
GHSA-9fvj-xqr2-xwg8
Sep 17, 2025
Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Denial of service when computing scalar multiplication using fake-GLV algorithm in github.com/consensys/gnark Fixed in
0.13.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-57801
GO-2025-3912
GHSA-95v9-hv42-pwrj
Aug 29, 2025
Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark Fixed in
0.14.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45039
GO-2024-3122
GHSA-q3hw-3gm4-w5cr
Nov 20, 2024
Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark Fixed in
0.11.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-50354
GO-2024-3244
GHSA-cph5-3pgr-c82g
Nov 01, 2024
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark Fixed in
0.12.0
References Updated Feb 06, 2025 · Source: OSV.dev
CVE-2024-45040
GO-2024-3123
GHSA-9xcg-3q8v-7fq6
Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark Fixed in
0.11.0
References Updated Sep 13, 2024 · Source: OSV.dev
GO-2023-2333
GHSA-rjjm-x32p-m3f7
Nov 15, 2023
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark Fixed in
0.9.2-0.20231110170422-f528807119e9
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-2119
GHSA-7p92-x423-vwj6
Oct 24, 2023
Proof forgery due to insufficient randomness in github.com/consensys/gnark A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract. Fixed in
0.9.1
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-44378
GO-2023-2098
GHSA-498w-5j49-vqjg
Oct 09, 2023
Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark Fixed in
0.9.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.1.0-alpha
pre
Dependencies (6)
|