PT-2026-103347 · Unknown · Ultrafastsecp256K1

·

CVE-2026-55174

·

Published

2026-09-30

·

Updated

2026-09-30

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions UltrafastSecp256k1 versions prior to 4.2.0
Description The ECDSA adaptor pre-signature verification in UltrafastSecp256k1 accepts forged adaptor pre-signatures. This occurs because the r value is not cryptographically bound to the adaptor point T due to a missing DLEQ binding. DLEQ binding is a cryptographic proof that ensures a secret key used in one context is the same as the one used in another.
Recommendations Update to version 4.2.0.

Exploit

Fix

Insufficient Verification of Data Authenticity

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55174
GHSA-C7Q2-GV3G-RGXM

Affected Products

Ultrafastsecp256K1