CVE-2026-1229
ADVISORY - githubSummary
The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signing relying on this curve are not affected.
The bug was fixed in v1.6.3.
EPSS Score: 0.00013 (0.020)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Incorrect Calculation
ADVISORY - github
Incorrect Calculation
NIST
CREATED
UPDATED
ADVISORY IDCVE-2026-1229
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
2.9lowGitHub
CREATED
UPDATED
ADVISORY IDGHSA-q9hv-hpm4-hj6x
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
2.9lowUbuntu
CREATED
UPDATED
ADVISORY IDCVE-2026-1229
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-