Description
UltrafastSecp256k1 is a high-performance, multi-backend secp256k1 engine with reproducible audit evidence, compatibility shims, and profile-based review scopes. Prior to version 4.2.0, UltrafastSecp256k1's ECDSA adaptor pre-signature verification accepts forged adaptor pre-signatures whose "r" value is not cryptographically bound to the adaptor point "T". This issue has been patched in version 4.2.0.
Published: 2026-09-30
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Potential forgery of ECDSA adaptor signatures leading to compromised cryptographic integrity
Action: Update Library
AI Analysis

Impact

UltrafastSecp256k1’s ECDSA adaptor verification omitted a proof of knowledge that binds the ‘r’ component of a pre‑signature to the adaptor point ‘T’. The missing DLEQ binding means adversaries can supply a forged adaptor pre‑signature whose ‘r’ value is not tied to ‘T’. If accepted, the verifier may accept a signature that can be used outside the intended cryptographic protocol, effectively enabling signature forgery or malicious manipulation of the cryptographic state. This weakness directly undermines the integrity guarantees of any system that relies on these adaptor signatures for authentication or transaction authorization.

Affected Systems

The vulnerability affects the shrec UltrafastSecp256k1 library in all releases before version 4.2.0. Applications that link to those versions and perform adaptor signature verification are at risk. Versions 4.2.0 and later contain the fix and are not affected.

Risk and Exploitability

The CVSS score of 5.9 classifies the flaw as moderate; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no known exploitation reports. The attack likely requires the ability to influence or supply a pre‑signature to the verifier—typically a local or compromised application context. Because the flaw is tied to cryptographic logic, an active adversary who can inject or replace an adaptor pre‑signature could cause the verifier to accept forged data, leading to potential denial of service, authentication bypass, or transaction manipulation depending on the application.

Generated by OpenCVE AI on September 30, 2026 at 19:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to UltrafastSecp256k1 version 4.2.0 or later where the DLEQ binding is enforced.
  • Recompile all dependent code that links against the library to ensure the new version is used.
  • If an upgrade is not immediately possible, restrict or audit any code paths that perform adaptor pre‑signature verification to reject signatures lacking proper binding or disable the feature entirely as a temporary workaround.

Generated by OpenCVE AI on September 30, 2026 at 19:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description UltrafastSecp256k1 is a high-performance, multi-backend secp256k1 engine with reproducible audit evidence, compatibility shims, and profile-based review scopes. Prior to version 4.2.0, UltrafastSecp256k1's ECDSA adaptor pre-signature verification accepts forged adaptor pre-signatures whose "r" value is not cryptographically bound to the adaptor point "T". This issue has been patched in version 4.2.0.
Title UltrafastSecp256k1: ECDSA adaptor verification accepts non-adaptable pre-signatures due to missing DLEQ binding
Weaknesses CWE-345
CWE-347
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-30T19:52:01.569Z

Reserved: 2026-06-16T15:20:43.085Z

Link: CVE-2026-55174

cve-icon Vulnrichment

Updated: 2026-09-30T19:51:33.995Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T16:17:31.457

Modified: 2026-09-30T20:17:33.243

Link: CVE-2026-55174

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T19:15:07Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity

  • CWE-347

    Improper Verification of Cryptographic Signature