Skip to content

Conversation

@rugk
Copy link
Contributor

@rugk rugk commented Dec 6, 2025

@trailofbits discovered a vulnerability here with this tool, so I thought why not add this?

This is just a quick draft.

/cc @Markus-MS

@rugk rugk changed the title Add CVE-2024-48949 to loft of vulnerabilities being found Add CVE-2024-48949 etc. to docs of vulnerabilities being found Dec 10, 2025
Trail of Bits found several CVEs in the Javascript `elliptic` package
using Wycheproof test vectors. These are described in their blog post,
and in an upstream PR.

Co-authored-by: Daniel McCarney <[email protected]>
@cpu
Copy link
Member

cpu commented Dec 15, 2025

Thanks @rugk, @Markus-MS.

@cpu cpu merged commit a92a003 into C2SP:main Dec 15, 2025
1 check passed
@rugk rugk deleted the patch-1 branch December 15, 2025 20:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants