Junglewise Threat Intelligence

CVE-2024-48949: Elliptic EdDSA signature malleability via missing validation

CVE-2024-48949 · Severity: low · CVSS 3.1 · Published 2024-10-10

Technologies: elliptic (npm). Vendors: npm.

Executive brief

Elliptic is a widely-used cryptography library for JavaScript (10+ million downloads weekly) that implements elliptic curve signature schemes. A flaw in its EdDSA signature verification allows attackers to forge alternative valid signatures for known message-signature pairs by omitting a required bounds check. This breaks the assumption of signature uniqueness, potentially compromising systems that rely on this property for authentication, consensus protocols, or data integrity.

Technical details

The vulnerability is a missing cryptographic validation in the EdDSA verify function (lib/elliptic/eddsa/index.js). The FIPS 186-5 standard requires verifying that the signature component 's' satisfies 0 ≤ s < n (where n is the order of the base point). Elliptic omits the check `if (sig.S().gte(sig.eddsa.curve.n) || sig.S().isNeg())`, allowing malformed signatures to pass validation. An attacker with knowledge of a valid (message, signature) pair can derive alternative valid signatures sig' where s' ≡ s (mod n), exploiting signature malleability. The attack requires no authentication and is network-reachable for any system using the library. This is classified as CWE-347 (Improper Verification of Cryptographic Signature). A fix adding the required bounds check was published in version 6.5.6.

Affected products

  • Elliptic (indutny) elliptic versions < 6.5.6

Timeline

  • 2024-10-10: disclosed: Vulnerability published as GHSA-434g-2637-qmqr
  • 2024-07-17: patched: Fix merged in version 6.5.6
  • 2025-11-18: other: Trail of Bits published detailed analysis of the vulnerability

References

Related threats