CVE-2024-48948
The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading 0 bytes and when the order of the elliptic curve's base point is smaller than the hash, because of an _truncateToN anomaly. This leads to valid signatures being rejected. Legitimate transactions or communications may be incorrectly flagged as invalid.
Published:Oct 15, 2024
Last Modified:Nov 25, 2025
EPS:Oct 15, 2024
EPSS Score:0.00116
CVSS Score:4.8
Affected Products
Vendor
Product
Action
Vendor
Indutny
Product
Elliptic
Indutny
Elliptic
Vendor
Nodejs
Product
Elliptic
Nodejs
Elliptic
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
