Executive brief
Elliptic is a widely-used cryptography library for JavaScript (10+ million downloads weekly) that implements elliptic curve signature schemes. A flaw in its EdDSA signature verification allows attackers to forge alternative valid signatures for known message-signature pairs by omitting a required bounds check. This breaks the assumption of signature uniqueness, potentially compromising systems that rely on this property for authentication, consensus protocols, or data integrity.
Technical details
The vulnerability is a missing cryptographic validation in the EdDSA verify function (lib/elliptic/eddsa/index.js). The FIPS 186-5 standard requires verifying that the signature component 's' satisfies 0 ≤ s < n (where n is the order of the base point). Elliptic omits the check `if (sig.S().gte(sig.eddsa.curve.n) || sig.S().isNeg())`, allowing malformed signatures to pass validation. An attacker with knowledge of a valid (message, signature) pair can derive alternative valid signatures sig' where s' ≡ s (mod n), exploiting signature malleability. The attack requires no authentication and is network-reachable for any system using the library. This is classified as CWE-347 (Improper Verification of Cryptographic Signature). A fix adding the required bounds check was published in version 6.5.6.
Affected products
- Elliptic (indutny) elliptic versions < 6.5.6
Timeline
- 2024-10-10: disclosed: Vulnerability published as GHSA-434g-2637-qmqr
- 2024-07-17: patched: Fix merged in version 6.5.6
- 2025-11-18: other: Trail of Bits published detailed analysis of the vulnerability
References
- https://github.com/indutny/elliptic/commit/7ac5360118f74eb02da73bdf9f24fd0c72ff5281
- https://blog.trailofbits.com/2025/11/18/we-found-cryptography-bugs-in-the-elliptic-library-using-wycheproof
- https://github.com/indutny/elliptic
- https://github.com/indutny/elliptic/compare/v6.5.5...v6.5.6
- https://security.netapp.com/advisory/ntap-20241227-0003