Signature Forgery Vulnerability in sm-crypto JavaScript Library by JuneAndGreen
CVE-2026-23965
7.5HIGH
What is CVE-2026-23965?
The sm-crypto library, which provides JavaScript implementations of important Chinese cryptographic algorithms, is vulnerable to a signature forgery attack. In versions prior to 0.4.0, an attacker can exploit flaws in the SM2 signature verification logic, allowing the creation of valid signatures for any public key under default configurations. This vulnerability arises when the message space has enough redundancy, enabling the attacker to manipulate the signature's associated message to meet specific formatting requirements. Users are advised to upgrade to version 0.4.0 to resolve this security issue.
Affected Version(s)
sm-crypto < 0.4.0
