CVE-2026-1229

ADVISORY - github

Summary

The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signing relying on this curve are not affected.

The bug was fixed in v1.6.3.

EPSS Score: 0.00013 (0.020)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Incorrect Calculation

ADVISORY - github

Incorrect Calculation


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in