CLEANSTART-2026-VP63638

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-VP63638.json
JSON Data
https://api.osv.dev/v1/vulns/CLEANSTART-2026-VP63638
Upstream
Published
2026-10-08T00:43:20Z
Modified
2026-10-08T16:47:14Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs
Details

CVE-2026-1229 affects multiple packages. The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. See references for individual vulnerability details.

References

Affected packages

CleanStart / opentofu

Package

Name
opentofu
Purl
pkg:apk/cleanstart/opentofu

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.11.5-r0

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-VP63638.json"

CleanStart / vault

Package

Name
vault
Purl
pkg:apk/cleanstart/vault

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.19.5-r6

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-VP63638.json"