VendorsConsensysgnark-cryptoall versions
Vulnerabilities

Consensys gnark-crypto

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2023-44273
Consensys gnark-crypto through 0.11.2 allows Signature Malleability. This occurs because deserialisation of EdDSA and ECDSA signatures does not ensure that the data is in a certain interval.
Published 2023-09-28 · Modified
9.8EPSS 0.008
CVE-2024-45039
gnark's Groth16 commitment extension unsound for more than one commitment
Published 2024-09-06 · Analyzed
6.2EPSS 0.002
CVE-2024-45040
gnark's commitments to private witnesses in Groth16 as implemented break zero-knowledge property
Published 2024-09-06 · Analyzed
5.9EPSS 0.004