Skip to content

[GHSA-2w8x-224x-785m] sjcl is missing point-on-curve validation in sjcl.ecc.basicKey.publicKey#7223

Closed
wmorland wants to merge 1 commit intowmorland/advisory-improvement-7223from
wmorland-GHSA-2w8x-224x-785m
Closed

[GHSA-2w8x-224x-785m] sjcl is missing point-on-curve validation in sjcl.ecc.basicKey.publicKey#7223
wmorland wants to merge 1 commit intowmorland/advisory-improvement-7223from
wmorland-GHSA-2w8x-224x-785m

Conversation

@wmorland
Copy link

Updates

  • Affected products
  • CVSS v3
  • CVSS v4

Comments
Adding patched version 1.0.9 https://github.com/bitwiseshiftleft/sjcl?tab=readme-ov-file#security-advisories

@github-actions github-actions bot changed the base branch from main to wmorland/advisory-improvement-7223 March 24, 2026 11:16
@wmorland
Copy link
Author

Replaced by #7225 which is cleaner

@wmorland wmorland closed this Mar 24, 2026
@github-actions github-actions bot deleted the wmorland-GHSA-2w8x-224x-785m branch March 24, 2026 12:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant