Timing Attack Vulnerability in OpenSSL's ECDSA and SM2 Signature Operations
CVE-2026-54872

Currently unrated

Key Information:

Vendor

OpenSSL

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-54872?

A timing attack vulnerability exists in the generic elliptic-curve scalar multiplication utilized for ECDSA and SM2 signature operations. This issue arises specifically when using curves that lack a dedicated constant-time implementation, leading to information leakage about the secret nonce via observable timing discrepancies. Although the timing leak is minimal and requires extensive measurements, an attacker can exploit this vulnerability to derive the private key through lattice attacks or Hidden Number Problem attacks by analyzing multiple signature timings. OpenSSL implementations using specific prime curves without constant-time measures are particularly at risk, while NIST-approved curves remain secure due to their dedicated implementations.

Affected Version(s)

OpenSSL 4.0.0 < 4.0.3

OpenSSL 3.6.0 < 3.6.5

OpenSSL 3.5.0 < 3.5.9

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Igor Ustinov
.