Junglewise Threat Intelligence

CVE-2020-13822: elliptic ECDSA signature malleability via encoding variations

CVE-2020-13822 · Severity: low · CVSS 3.1 · Published 2020-07-29

Technologies: elliptic (npm). Vendors: npm.

Executive brief

The elliptic library is a widely-used cryptographic library for Node.js that implements elliptic curve operations, including ECDSA signature verification. An application relying on ECDSA signatures for transaction validation, blockchain operations, or cryptographic authentication could be vulnerable to signature malleability attacks, where an attacker crafts alternative encodings of valid signatures that pass verification but weren't created by the legitimate signer. This could enable unauthorized transactions, key theft, or account takeovers depending on how signatures are used.

Technical details

The vulnerability is a signature malleability issue in ECDSA verification within the elliptic library (versions before 6.5.3). The root cause is insufficient encoding validation: the library accepts ECDSA signatures that deviate from strict DER encoding standards, including long-form length encoding, leading zeros in length fields, and integer overflow conditions in ASN.1 parsing. An attacker can craft multiple distinct byte sequences representing the same (r, s) signature pair that all pass verification, violating the principle of canonical signatures. The attack requires network access to trigger signature verification on attacker-controlled input (no authentication required). This could enable double-spending in blockchain systems or key recovery in applications that assume signature uniqueness. The fix was released in version 6.5.3 with proper ASN.1 encoding validation.

Affected products

  • elliptic elliptic before 6.5.3

Timeline

  • 2020-07-29: disclosed
  • 2020-07-29: patched: Fixed in version 6.5.3

References

Related threats