Signature Malleability Vulnerability in sm-crypto Library by JuneAndGreen
CVE-2026-23967

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
22 January 2026

What is CVE-2026-23967?

The sm-crypto library, notable for its JavaScript implementations of China's cryptographic standards (SM2, SM3, SM4), contains a signature malleability vulnerability within its SM2 signature verification mechanism. This flaw allows attackers to generate new, valid signatures for previously signed messages, potentially undermining the integrity of the signed data. Versions prior to 0.3.14 are impacted, and users are strongly urged to upgrade to this version to mitigate the risk.

Affected Version(s)

sm-crypto < 0.3.14

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.