Consensys gnark-crypto through 0.11.2 allows Signature Malleability. This occurs because deserialisation of EdDSA and ECDSA signatures does not ensure that the data is in a certain interval.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/Consensys/gnark-crypto(Go) | 0 | 0.12.0 | N/A |
| github.com/consensys/gnark-crypto(Go) | 0 | 0.12.0 | N/A |
CVSS Metrics