CVE Explorer
CVE-2026-1229
The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas.
ECDH and ECDSA signing relying on this curve are not affected.
The bug was fixed in v1.6.3 https://github.com/cloudflare/circl/releases/tag/v1.6.3 .
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","platforms":["Go"],"product":"CIRCL","repo":"https://github.com/cloudflare/circl","vendor":"Cloudflare","versions":[{"lessThan":"1.6.3","status":"affected","version":"CIRCL up to version 1.6.2","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:cc617fab42a9ce5d1a81c56bc67bb9e80fd1d6698b22343233a72c483ac4da3e · sha256:2037080f3ba3f289… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"YES","Recovery":"NOT_DEFINED","Safety":"NEGLIGIBLE","attackComplexity":"HIGH","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":2.9,"baseSeverity":"LOW","exploitMaturity":"PROOF_OF_CONCEPT","privilegesRequired":"NONE","providerUrgency":"AMBER","subAvailabilityImpact":"LOW","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P/S:N/AU:Y/U:Amber","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityIm…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:cc617fab42a9ce5d1a81c56bc67bb9e80fd1d6698b22343233a72c483ac4da3e · sha256:2037080f3ba3f289… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-682","description":"CWE-682 Incorrect Calculation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:cc617fab42a9ce5d1a81c56bc67bb9e80fd1d6698b22343233a72c483ac4da3e · sha256:2037080f3ba3f289… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://github.com/cloudflare/circl"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:cc617fab42a9ce5d1a81c56bc67bb9e80fd1d6698b22343233a72c483ac4da3e · sha256:2037080f3ba3f289… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.