VYPR
Medium severity4.3OSV Advisory· Published Mar 13, 2025· Updated Apr 15, 2026

CVE-2020-36843

CVE-2020-36843

Description

The implementation of EdDSA in EdDSA-Java (aka ed25519-java) through 0.3.0 exhibits signature malleability and does not satisfy the SUF-CMA (Strong Existential Unforgeability under Chosen Message Attacks) property. This allows attackers to create new valid signatures different from previous signatures for a known message.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
net.i2p.crypto:eddsaMaven
<= 0.3.0
net.i2p:i2pMaven
< 0.9.390.9.39

Affected products

53

Patches

Vulnerability mechanics

References

5

News mentions

1