Junglewise Threat Intelligence

CVE-2025-57801: GO-2025-3912 - Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark

CVE-2025-57801 · Severity: low · CVSS 3.1 · Published 2025-08-29

Technologies: github.com/consensys/gnark (Go). Vendors: Go.

Executive brief

Gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks in github.com/consensys/gnark

Affected products

  • Go github.com/consensys/gnark

Related threats