Math Error in CIRCL Package by Cloudflare Affects ECDH and ECDSA Functionality
CVE-2026-1229

2.9LOW

Key Information:

Vendor

Cloudflare

Status
Vendor
CVE Published:
24 February 2026

What is CVE-2026-1229?

A mathematical error in the CombinedMult function of the CIRCL ecc/p384 package leads to incorrect value generation under certain input conditions. This can potentially compromise the integrity of cryptographic operations in applications using this curve. The issue has been addressed in version 1.6.3, where complete addition formulas are now employed to ensure accuracy in computations. Applications reliant on ECDH and ECDSA signing utilizing the secp384r1 curve are not affected by this bug.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

CIRCL Go CIRCL up to version 1.6.2 < 1.6.3

References

CVSS V4

Score:
2.9
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Guido Vranken
.