{"id":"CVE-2022-41340","aliases":["GHSA-q3f4-9h4p-vgr3"],"url":"https://o3.security/vulnerability/CVE-2022-41340","summary":"secp256k1-js implements ECDSA without required r and s validation, leading to signature forgery","details":"The secp256k1-js package before 1.1.0 for Node.js implements ECDSA without required r and s validation, leading to signature forgery.","published":"2022-09-24T18:22:27Z","modified":"2026-07-15T01:49:15.627101695Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@lionello/secp256k1-js","fixedVersion":"1.1.0"}],"fix":{"url":"https://github.com/lionello/secp256k1-js/commit/302800f0370b42e360a33774bb808274ac729c2e","label":"lionello/secp256k1-js@302800f"},"references":[{"type":"WEB","url":"https://github.com/lionello/secp256k1-js/compare/1.0.1...1.1.0"},{"type":"WEB","url":"https://www.npmjs.com/package/%40lionello/secp256k1-js"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/41xxx/CVE-2022-41340.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-41340"},{"type":"REPORT","url":"https://github.com/lionello/secp256k1-js/issues/11"},{"type":"FIX","url":"https://github.com/lionello/secp256k1-js/commit/302800f0370b42e360a33774bb808274ac729c2e"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:15.627101695Z"}}