Medium severity6.8NVD Advisory· Published Feb 2, 2021· Updated Jun 17, 2026
CVE-2020-28498
CVE-2020-28498
Description
The package elliptic before 6.5.4 are vulnerable to Cryptographic Issues via the secp256k1 implementation in elliptic/ec/key.js. There is no check to confirm that the public key point passed into the derive function actually exists on the secp256k1 curve. This results in the potential for the private key used in this implementation to be revealed after a number of ECDH operations are performed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ellipticnpm | < 6.5.4 | 6.5.4 |
Affected products
3- elliptic/ellipticdescription
Patches
Vulnerability mechanics
References
8- github.com/indutny/elliptic/commit/441b7428b0e8f6636c42118ad2aaa186d3c34c3fnvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1069836nvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-ELLIPTIC-1064899nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-r9p9-mrjm-926wghsaADVISORY
- github.com/christianlundkvist/blog/blob/master/2020_05_26_secp256k1_twist_attacks/secp256k1_twist_attacks.mdnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-28498ghsaADVISORY
- github.com/indutny/elliptic/pull/244/commitsghsaWEB
- www.npmjs.com/package/ellipticghsaWEB
News mentions
0No linked articles in our index yet.