Executive brief
StableLib's Ed25519 library is used to verify digital signatures in cryptographic applications. Due to a missing validation check, an attacker can create multiple valid signatures for the same message without knowing the private key. This could allow attackers to bypass deduplication systems, forge transaction identities in blockchain applications, or bypass signature-based access controls that assume signature uniqueness.
Technical details
The vulnerability is a signature malleability issue (CWE-347) caused by missing validation of the S component of Ed25519 signatures. The verify() function in @stablelib/ed25519 does not check that S is less than the group order L, as recommended by CFRG and required by ZIP-215. An attacker observing a valid signature (R, S) can add the group order L to the S component to produce a second valid signature (R, S + L) for the same message without possessing the private key. This is a network-reachable vulnerability with no authentication required. The attack produces alternate valid signatures but does not enable signing new messages; impact is limited to systems that depend on signature value uniqueness. The issue affects versions ≤ 2.0.2 of @stablelib/ed25519.
Affected products
- StableLib ed25519 ≤ 2.0.2
Timeline
- 2026-04-01: disclosed: Advisory published