GHSA-p53j-g8pw-4w5f

    Dashboard / Vulnerabilities / GHSA-p53j-g8pw-4w5f

    GHSA-p53j-g8pw-4w5f

    Published: 13 Mar 2025Last Modified: 10 Sept 2026

    Summary: Ed25519 Signature Malleability in ed25519-java Due to Missing Scalar Range Check

    Details: The implementation of EdDSA in EdDSA-Java (aka ed25519-java) through 0.3.0 exhibits signature malleability and does not satisfy the SUF-CMA (Strong Existential Unforgeability under Chosen Message Attacks) property. This allows attackers to create new valid signatures different from previous signatures for a known message.

    Affected packages

    Package

    Name: net.i2p.crypto:eddsa

    Purl: pkg:maven/net.i2p.crypto/eddsa

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    0.1.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-p53j-g8pw-4w5f | CVE-DB