Private Key Recovery Vulnerability in sm-crypto JavaScript Library
CVE-2026-23966

9.1CRITICAL

Key Information:

Status
Vendor
CVE Published:
22 January 2026

What is CVE-2026-23966?

The sm-crypto library, which implements the Chinese cryptographic algorithms SM2, SM3, and SM4, contains a vulnerability in its SM2 decryption logic prior to version 0.3.14. An attacker can exploit this weakness by interacting with the SM2 decryption interface multiple times, enabling them to recover the private key in a matter of several hundred interactions. This vulnerability poses a significant risk to the security of applications utilizing the affected versions of the library. Version 0.3.14 has been released to address this issue.

Affected Version(s)

sm-crypto < 0.3.14

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.