A private key recovery vulnerability exists in the SM2 decryption logic of sm-crypto. By interacting with the SM2 decryption interface multiple times, an attacker can fully recover the private key within approximately several hundred interactions.
This vulnerability was discovered by:
{
"cwe_ids": [
"CWE-345"
],
"github_reviewed": true,
"github_reviewed_at": "2026-01-21T16:13:25Z",
"nvd_published_at": "2026-01-22T03:15:47Z",
"severity": "CRITICAL"
}