wolfSSL's ECCSI signature verifier `wc_VerifyEccsiHash`...
High severity
Unreviewed
Published
Apr 10, 2026
to the GitHub Advisory Database
•
Updated Apr 29, 2026
Description
Published by the National Vulnerability Database
Apr 10, 2026
Published to the GitHub Advisory Database
Apr 10, 2026
Last updated
Apr 29, 2026
wolfSSL's ECCSI signature verifier
wc_VerifyEccsiHashdecodes therandsscalars from the signature blob viamp_read_unsigned_binwith no check that they lie in[1, q-1]. A crafted forged signature could verify against any message for any identity, using only publicly-known constants.References