The ed25519-dalek crate before 2 for Rust allows a double public key signing function oracle attack. The Keypair implementation leads to a simple computation for extracting a private key.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| ed25519-dalek(crates.io) | 0 | 2.0.0 | N/A |
CVSS Metrics