{"id":"CVE-2022-41340","details":"The secp256k1-js package before 1.1.0 for Node.js implements ECDSA without required r and s validation, leading to signature forgery.","aliases":["GHSA-q3f4-9h4p-vgr3"],"modified":"2026-08-12T03:51:32.490165930Z","published":"2022-09-24T18:22:27Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/41xxx/CVE-2022-41340.json"},"references":[{"type":"WEB","url":"https://github.com/lionello/secp256k1-js/compare/1.0.1...1.1.0"},{"type":"WEB","url":"https://www.npmjs.com/package/%40lionello/secp256k1-js"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/41xxx/CVE-2022-41340.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-41340"},{"type":"REPORT","url":"https://github.com/lionello/secp256k1-js/issues/11"},{"type":"FIX","url":"https://github.com/lionello/secp256k1-js/commit/302800f0370b42e360a33774bb808274ac729c2e"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/lionello/secp256k1-js","events":[{"introduced":"0"},{"fixed":"200ec679888d5ad85b1a9b38b18640e788f43760"},{"fixed":"302800f0370b42e360a33774bb808274ac729c2e"}],"database_specific":{"cpe":"cpe:2.3:a:secp256k1-js_project:secp256k1-js:*:*:*:*:*:node.js:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.1.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-41340.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}