Signature Malleability Vulnerability in sm-crypto Library by JuneAndGreen
CVE-2026-23967
7.5HIGH
What is CVE-2026-23967?
The sm-crypto library, notable for its JavaScript implementations of China's cryptographic standards (SM2, SM3, SM4), contains a signature malleability vulnerability within its SM2 signature verification mechanism. This flaw allows attackers to generate new, valid signatures for previously signed messages, potentially undermining the integrity of the signed data. Versions prior to 0.3.14 are impacted, and users are strongly urged to upgrade to this version to mitigate the risk.
Affected Version(s)
sm-crypto < 0.3.14
