sm-crypto Affected by Private Key Recovery in SM2-PKE
Critical severity
GitHub Reviewed
Published
Jan 20, 2026
in
JuneAndGreen/sm-crypto
•
Updated Jan 22, 2026
Description
Published to the GitHub Advisory Database
Jan 21, 2026
Reviewed
Jan 21, 2026
Published by the National Vulnerability Database
Jan 22, 2026
Last updated
Jan 22, 2026
Summary
A private key recovery vulnerability exists in the SM2 decryption logic of sm-crypto. By interacting with the SM2 decryption interface multiple times, an attacker can fully recover the private key within approximately several hundred interactions.
Credit
This vulnerability was discovered by:
References