-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 0xCERT Security Advisory 0xCERT-2026-0214 ============================================================ Advisory-ID: 0xCERT-2026-0214 Severity: Low Published: 2026-01-08T21:30:34.000Z Updated: 2026-10-08T22:48:24.963Z Chains: n/a URL: https://www.0xcert.com/advisory/0xCERT-2026-0214 Title: Elliptic Uses a Cryptographic Primitive with a Risky Implementation Summary - ------- Elliptic Uses a Cryptographic Primitive with a Risky Implementation. The ECDSA implementation of the Elliptic package generates incorrect signatures if an interim value of 'k' (as computed based on step 3.2 of RFC 6979 https://datatracker. Details - ------- Summary The ECDSA implementation of the Elliptic package generates incorrect signatures if an interim value of 'k' (as computed based on step 3.2 of RFC 6979 https://datatracker. Affected - - elliptic (npm) <= 6.6.1 — no patched version listed Severity Low (CVSS 2.9), as rated by the upstream advisory. Recommended actions - - No fixed version is listed upstream; apply the mitigations in the source advisory and monitor for a release Source & attribution This 0xCERT advisory summarises GHSA-848j-6mx2-7j84 / CVE-2025-14505 from the GitHub Advisory Database: https://github.com/advisories/GHSA-848j-6mx2-7j84. Details may change; refer to the original source for the authoritative record. References - ---------- - - https://github.com/advisories/GHSA-848j-6mx2-7j84 - - CVE-2025-14505 - - https://nvd.nist.gov/vuln/detail/CVE-2025-14505 - - https://github.com/indutny/elliptic/issues/321 - - https://www.herodevs.com/vulnerability-directory/cve-2025-14505 Verify with the 0xCERT OpenPGP key: https://www.0xcert.com/pgp.asc Fingerprint: 5F94 3ED1 1E50 CF31 2128 C493 CCC7 D9EC 9415 723D -----BEGIN PGP SIGNATURE----- wrsEARYKAG0FgmrI9YEJEDe9Tbcr+ZxrRRQAAAAAABwAIHNhbHRAbm90YXRp b25zLm9wZW5wZ3Bqcy5vcmcBhujyrterhpktrqifH3dVGZoAdQatut5PbbIk jyQ9sRYhBGCkkFZbJcT5QWu27ze9Tbcr+ZxrAACx7gD8D+oKI0n017AO+9Yg Mk47W9rczkGh4xsIocNAcCoUfLABAIO5Zt7kn8bMBs18gWEFi9N10r9/3ncQ EMrQlLS2Gd8E =HTGo -----END PGP SIGNATURE-----