PT-2025-35319 · Gnark +1 · Gnark +1

Feltroidprime

·

Published

2025-08-29

·

Updated

2025-08-30

·

CVE-2025-58157

CVSS v3.1
7.5
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Name of the Vulnerable Software and Affected Versions:

gnark versions prior to 0.13.0

Description:

gnark is a zero-knowledge proof system framework. A denial of service issue can occur when computing scalar multiplication using the fake-GLV algorithm in versions prior to 0.13.0. This is due to the algorithm not converging quickly enough for certain inputs, potentially causing the prover to get stuck in a slow loop if accepting untrusted witness data.

Recommendations:

Update gnark to version 0.13.0 or later.

Update the gnark-crypto dependency to the fixed version.

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2025-58157
GHSA-9FVJ-XQR2-XWG8

Affected Products

Gnark
Gnark-Crypto