Junglewise Threat Intelligence

CVE-2023-44273: GO-2025-4027 - Gnark-crypto doesn't range check input values during ECDSA and EdDSA deserialization in github.com/consensys/gnark-crypto

CVE-2023-44273 · Severity: low · CVSS 3.1 · Published 2025-10-30

Technologies: github.com/Consensys/gnark-crypto (Go). Vendors: Go.

Executive brief

Gnark-crypto doesn't range check input values during ECDSA and EdDSA deserialization in github.com/consensys/gnark-crypto

Affected products

  • Go github.com/Consensys/gnark-crypto

Related threats