CVE Feed

    Dashboard / CVE / CVE-2026-4258

    CVE-2026-4258

    Versions of the package sjcl before 1.0.9 are vulnerable to Improper Verification of Cryptographic Signature due to missing point-on-curve validation in sjcl.ecc.basicKey.publicKey(). An attacker can recover a victim's ECDH private key by sending crafted off-curve public keys and observing ECDH outputs. The dhJavaEc() function directly returns the raw x-coordinate of the scalar multiplication result (no hashing), providing a plaintext oracle without requiring any decryption feedback.

    Published:Mar 17, 2026
    Last Modified:Jul 28, 2026
    EPS:Mar 17, 2026
    EPSS Score:0.00246
    CVSS Score:7.5

    Affected Products

    Vendor
    Bitwiseshiftleft
    Product
    Sjcl
    Vendor
    Bitwiseshiftleft
    Product
    Stanford Javascript Crypto Library

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High