Medium severity5.9NVD Advisory· Published Jul 28, 2025· Updated Apr 15, 2026
CVE-2022-50237
CVE-2022-50237
Description
The ed25519-dalek crate before 2 for Rust allows a double public key signing function oracle attack. The Keypair implementation leads to a simple computation for extracting a private key.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ed25519-dalekcrates.io | < 2.0.0 | 2.0.0 |
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.