Executive brief
SM2-PKE has Unchecked AffinePoint Decoding (unwrap) in decrypt()
Affected products
- crates.io sm2
Junglewise Threat Intelligence
CVE-2026-22699 · Severity: low · CVSS 3.1 · Published 2026-01-09
Technologies: sm2 (crates.io). Vendors: crates.io.
SM2-PKE has Unchecked AffinePoint Decoding (unwrap) in decrypt()