Signature Forgery Vulnerability in sm-crypto JavaScript Library by JuneAndGreen
CVE-2026-23965

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
22 January 2026

What is CVE-2026-23965?

The sm-crypto library, which provides JavaScript implementations of important Chinese cryptographic algorithms, is vulnerable to a signature forgery attack. In versions prior to 0.4.0, an attacker can exploit flaws in the SM2 signature verification logic, allowing the creation of valid signatures for any public key under default configurations. This vulnerability arises when the message space has enough redundancy, enabling the attacker to manipulate the signature's associated message to meet specific formatting requirements. Users are advised to upgrade to version 0.4.0 to resolve this security issue.

Affected Version(s)

sm-crypto < 0.4.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.