{"id":"GHSA-9xfq-8j3r-xp5g","summary":"Duplicate Advisory: Consensys gnark-crypto allows Signature Malleability","details":"## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-fr8m-434r-g3xp. This link is maintained to preserve external references.\n\n## Original Description\nConsensys gnark-crypto through 0.11.2 allows Signature Malleability. This occurs because deserialisation of EdDSA and ECDSA signatures does not ensure that the data is in a certain interval.","aliases":["CVE-2023-44273","GHSA-fr8m-434r-g3xp","GO-2023-2096","GO-2025-4027"],"modified":"2026-02-03T03:09:31.212457Z","published":"2023-09-28T06:30:20Z","withdrawn":"2026-01-22T20:44:23Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2023-09-28T16:42:58Z","nvd_published_at":"2023-09-28T04:15:12Z","cwe_ids":["CWE-502"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-44273"},{"type":"WEB","url":"https://github.com/Consensys/gnark-crypto/pull/449"},{"type":"PACKAGE","url":"https://github.com/Consensys/gnark-crypto"},{"type":"WEB","url":"https://github.com/Consensys/gnark-crypto/releases"},{"type":"WEB","url":"https://github.com/Consensys/gnark-crypto/releases/tag/v0.12.0"},{"type":"WEB","url":"https://verichains.io"}],"affected":[{"package":{"name":"github.com/Consensys/gnark-crypto","ecosystem":"Go","purl":"pkg:golang/github.com/Consensys/gnark-crypto"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.12.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/09/GHSA-9xfq-8j3r-xp5g/GHSA-9xfq-8j3r-xp5g.json"}},{"package":{"name":"github.com/consensys/gnark-crypto","ecosystem":"Go","purl":"pkg:golang/github.com/consensys/gnark-crypto"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.12.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/09/GHSA-9xfq-8j3r-xp5g/GHSA-9xfq-8j3r-xp5g.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}