{"id":"CVE-2025-66017","summary":"CGGMP21 presignatures can be used in the way that significantly reduces security","details":"CGGMP24 is a state-of-art ECDSA TSS protocol that supports 1-round signing (requires 3 preprocessing rounds), identifiable abort, and a key refresh protocol. In versions 0.6.3 and prior of cggmp21 and version 0.7.0-alpha.1 of cggmp24, presignatures can be used in the way that significantly reduces security. cggmp24 version 0.7.0-alpha.2 release contains API changes that make it impossible to use presignatures in contexts in which it reduces security.","aliases":["GHSA-8frv-q972-9rq5","RUSTSEC-2025-0127","RUSTSEC-2025-0128"],"modified":"2026-08-12T03:51:11.239219511Z","published":"2025-11-25T19:59:07.956Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66017.json","unresolved_ranges":[{"extracted_events":[{"introduced":"cggmp21 \u003c= 0.6.3"},{"last_affected":"cggmp21 \u003c= 0.6.3"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"GitHub_M","cwe_ids":["CWE-327"]},"references":[{"type":"WEB","url":"https://www.dfns.co/article/cggmp21-vulnerabilities-patched-and-explained"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66017.json"},{"type":"ADVISORY","url":"https://github.com/LFDT-Lockness/cggmp21/security/advisories/GHSA-8frv-q972-9rq5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66017"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/lfdt-lockness/cggmp21","events":[{"introduced":"3199f8845338a27d941b53663daaf88c5c8226f0"},{"last_affected":"3199f8845338a27d941b53663daaf88c5c8226f0"}],"database_specific":{"extracted_events":[{"introduced":"cggmp24 = 0.7.0-alpha.1"},{"last_affected":"cggmp24 = 0.7.0-alpha.1"}],"source":"AFFECTED_FIELD"}}],"versions":["cggmp24 = 0.7.0-alpha.1","v0.7.0-alpha.1","paillier-zk-v0.7.0-alpha.1","cggmp24-keygen-v0.7.0-alpha.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66017.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}