Skip to content

[GHSA-2w8x-224x-785m] sjcl is missing point-on-curve validation in sjcl.ecc.basicKey.publicKey#7225

Open
wmorland wants to merge 1 commit intogithub:wmorland/advisory-improvement-7225from
wmorland:wmorland-GHSA-2w8x-224x-785m
Open

[GHSA-2w8x-224x-785m] sjcl is missing point-on-curve validation in sjcl.ecc.basicKey.publicKey#7225
wmorland wants to merge 1 commit intogithub:wmorland/advisory-improvement-7225from
wmorland:wmorland-GHSA-2w8x-224x-785m

Conversation

@wmorland
Copy link

Updates

  • Updates modified timestamp
  • Adds fixed version to affected ranges
  • Adds fix commit url to references

Comments
Adding patched version 1.0.9 https://github.com/bitwiseshiftleft/sjcl?tab=readme-ov-file#security-advisories

@wmorland wmorland force-pushed the wmorland-GHSA-2w8x-224x-785m branch from cd38666 to e698ac6 Compare March 24, 2026 12:20
@github-actions github-actions bot changed the base branch from main to wmorland/advisory-improvement-7225 March 24, 2026 12:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant