Private Key Recovery Vulnerability in sm-crypto JavaScript Library
CVE-2026-23966
9.1CRITICAL
What is CVE-2026-23966?
The sm-crypto library, which implements the Chinese cryptographic algorithms SM2, SM3, and SM4, contains a vulnerability in its SM2 decryption logic prior to version 0.3.14. An attacker can exploit this weakness by interacting with the SM2 decryption interface multiple times, enabling them to recover the private key in a matter of several hundred interactions. This vulnerability poses a significant risk to the security of applications utilizing the affected versions of the library. Version 0.3.14 has been released to address this issue.
Affected Version(s)
sm-crypto < 0.3.14
