PT-2026-3894 · Sm-Crypto · Sm-Crypto

·

CVE-2026-23967

·

Published

2026-01-21

·

Updated

2026-02-25

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions sm-crypto versions prior to 0.3.14
Description The sm-crypto library, providing JavaScript implementations of Chinese cryptographic algorithms SM2, SM3, and SM4, contains a signature malleability issue in its SM2 signature verification logic. An attacker can generate a new valid signature for a previously signed message using an existing signature.
Recommendations Update to version 0.3.14 or later.

Exploit

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-23967
GHSA-QV7W-V773-3XQM

Affected Products

Sm-Crypto