A private key recovery vulnerability exists in the SM2 decryption logic of sm-crypto. By interacting with the SM2 decryption interface multiple times, an attacker can fully recover the private key within approximately several hundred interactions.
This vulnerability was discovered by: - XlabAI Team of Tencent Xuanwu Lab - Atuin Automated Vulnerability Discovery Engine
{
"nvd_published_at": "2026-01-22T03:15:47Z",
"cwe_ids": [
"CWE-345"
],
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2026-01-21T16:13:25Z"
}