CVE-2026-1229
ADVISORY - githubSummary
The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signing relying on this curve are not affected.
The bug was fixed in v1.6.3.
EPSS Score: 0.00013 (0.020)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Incorrect Calculation
ADVISORY - github
Incorrect Calculation
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in