browserify / browserify/crypto-browserify

Dependency elliptic affected by CVE-2025-14505 (ECDSA signature vulnerability)

Open
#255 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
681
Forks
209
PR merge metrics
No merged PRs in 30d

Description

## Summary

The **elliptic** package (a dependency of crypto-browserify) is affected by CVE-2025-14505, causing incorrect ECDSA
signatures and potential private key exposure.

## Details

- **CVE:** [CVE-2025-14505](https://nvd.nist.gov/vuln/detail/CVE-2025-14505)
- **GHSA:** [GHSA-848j-6mx2-7j84](https://github.com/advisories/GHSA-848j-6mx2-7j84)
- **Affected:** elliptic ≤ 6.6.1 (all versions)
- **Upstream issue:** [indutny/elliptic#344](https://github.com/indutny/elliptic/issues/344)

## Impact

Incorrect signature generation when nonce **k** has leading zeros, potentially allowing private key recovery if attackers
obtain both faulty and correct signatures.

## Status

No patch is available yet. Tracking this issue to update the dependency once elliptic releases a fix.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.