When using ECDH-ES an attacker can mount an invalid curve attack during decryption as the supplied public key is not checked to be on the same curve as the receivers private key.
{
"review_status": "REVIEWED",
"url": "https://pkg.go.dev/vuln/GO-2020-0010"
}