sm-crypto Affected by Signature Malleability in SM2-DSA
High severity
GitHub Reviewed
Published
Jan 20, 2026
in
JuneAndGreen/sm-crypto
•
Updated Jan 22, 2026
Description
Published to the GitHub Advisory Database
Jan 21, 2026
Reviewed
Jan 21, 2026
Published by the National Vulnerability Database
Jan 22, 2026
Last updated
Jan 22, 2026
Summary
A signature malleability vulnerability exists in the SM2 signature verification logic of the sm-crypto library. An attacker can derive a new valid signature for a previously signed message from an existing signature.
Credit
This vulnerability was discovered by:
References