CVE-2026-23966

Source
https://cve.org/CVERecord?id=CVE-2026-23966
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23966.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-23966
Aliases
Published
2026-01-22T02:06:54.003Z
Modified
2026-01-28T05:53:06.771587Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
sm-crypto Affected by Private Key Recovery in SM2-PKE
Details

sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A private key recovery vulnerability exists in the SM2 decryption logic of sm-crypto prior to version 0.3.14. By interacting with the SM2 decryption interface multiple times, an attacker can fully recover the private key within approximately several hundred interactions. Version 0.3.14 patches the issue.

Database specific
{
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23966.json",
    "cwe_ids": [
        "CWE-345"
    ]
}
References

Affected packages

Git / github.com/juneandgreen/sm-crypto

Affected ranges

Type
GIT
Repo
https://github.com/juneandgreen/sm-crypto
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23966.json"