Critical severity9.1NVD Advisory· Published Aug 2, 2024· Updated Jun 17, 2026
CVE-2024-42461
CVE-2024-42461
Description
In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ellipticnpm | >= 5.2.1, < 6.5.7 | 6.5.7 |
Affected products
4- Node.js/Elliptic packagedescription
- ghsa-coords2 versions
>= 5.2.1, < 6.5.7+ 1 more
- (no CPE)range: >= 5.2.1, < 6.5.7
- (no CPE)range: < 0.7.0.4.git142.862ef23-1.1
- cpe:2.3:a:elliptic_project:elliptic:6.5.6:*:*:*:*:node.js:*:*
Patches
Vulnerability mechanics
References
6- github.com/indutny/elliptic/pull/317nvdIssue TrackingPatchWEB
- github.com/advisories/GHSA-49q7-c7j4-3p7mghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-42461ghsaADVISORY
- github.com/indutny/elliptic/commit/accb61e9c1a005e5c8ff96a8b33893100bb42d11ghsaWEB
- security.netapp.com/advisory/ntap-20241004-0005ghsaWEB
- security.netapp.com/advisory/ntap-20241004-0005/nvd
News mentions
0No linked articles in our index yet.