CVE-2026-46669
OpenVM is a performant and modular zkVM framework built for customization and extensibility. Prior to version 1.6.0, the openvm-pairing guest library's try_honest_pairing_check function invokes Theorem 3 of https://eprint.iacr.org/2024/640.pdf but does not check that the scaling factor s is in a proper subfield of Fp12. This allows incorrect results to the pairing check. This issue has been patched in version 1.6.0.
Published:Jun 10, 2026
Last Modified:Jun 12, 2026
EPS:Jun 10, 2026
EPSS Score:0.00085
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Openvm
Product
Openvm
Openvm
Openvm
Vendor
Openvm-org
Product
Openvm
Openvm-org
Openvm
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
