<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 01:58:16 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-276284</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-276284</link>
      <description>EUVD-2026-276284</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-276284</guid>
    </item>
    <item>
      <title>fkie_cve-2026-32614</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32614</link>
      <description>&lt;p&gt;Go ShangMi (Commercial Cryptography) Library (GMSM) is a cryptographic library that covers the Chinese commercial cryptographic public algorithms SM2/SM3/SM4/SM9/ZUC. Prior to 0.41.1, the current SM9 decryption implementation contains an infinity-point ciphertext forgery vulnerability. The root cause is that, during decryption, the elliptic-curve point C1 in the ciphertext is only deserialized and checked to be on the curve, but the implementation does not explicitly reject the point at infinity. In the current implementation, an attacker can construct C1 as the point at infinity, causing the bilinear pairing result to degenerate into the identity element in the GT group. As a result, a critical part of the key derivation input becomes a predictable constant. An attacker who only knows the target user&amp;#39;s UID can derive the decryption key material and then forge a ciphertext that passes the integrity check. This vulnerability is fixed in 0.41.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Go ShangMi (Commercial Cryptography) Library (GMSM) is a cryptographic library that covers the Chinese commercial cryptographic public algorithms SM2/SM3/SM4/SM9/ZUC. Prior to 0.41.1, the current SM9 decryption implementation contains an infinity-point ciphertext forgery vulnerability. The root cause is that, during decryption, the elliptic-curve point C1 in the ciphertext is only deserialized and checked to be on the curve, but the implementation does not explicitly reject the point at infinity. In the current implementation, an attacker can construct C1 as the point at infinity, causing the bilinear pairing result to degenerate into the identity element in the GT group. As a result, a critical part of the key derivation input becomes a predictable constant. An attacker who only knows the target user&amp;#39;s UID can derive the decryption key material and then forge a ciphertext that passes the integrity check. This vulnerability is fixed in 0.41.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-32614</guid>
    </item>
    <item>
      <title>GHSA-5xxp-2vrj-x855 — SM9 Infinity-Point Ciphertext Forgery Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5xxp-2vrj-x855</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/emmansun/gmsm&lt;/p&gt;
&lt;p&gt;## Overview&lt;/p&gt;
&lt;p&gt;The current SM9 decryption implementation contains an infinity-point ciphertext forgery vulnerability. The root cause is that, during decryption, the elliptic-curve point C1 in the ciphertext is only deserialized and checked to be on the curve, but the implementation does not explicitly reject the point at infinity.&lt;/p&gt;
&lt;p&gt;In the current implementation, an attacker can construct C1 as the point at infinity, causing the bilinear pairing result to degenerate into the identity element in the GT group. As a result, a critical part of the key derivation input becomes a predictable constant. An attacker who only knows the target user&amp;#39;s UID can derive the decryption key material and then forge a ciphertext that passes the integrity check.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;The direct impact of this vulnerability is ciphertext forgery, not confidentiality loss.&lt;/p&gt;
&lt;p&gt;- The attacker does not need the master public key, the user&amp;#39;s private key, or any other secret material.
- The attacker only needs to know the target UID to construct a seemingly valid ciphertext.
- When the recipient invokes the SM9 decryption API, the forged ciphertext decrypts successfully to attacker-chosen plaintext.
- The C3 integrity check also passes, so this is not merely a format bypass, but a full forgery.&lt;/p&gt;
&lt;p&gt;This issue affects the following paths because they all eventually enter the same `UnwrapKey` logic:&lt;/p&gt;
&lt;p&gt;- `sm9.Decrypt`
- `sm9.DecryptASN1`
- `sm9.UnwrapKey`&lt;/p&gt;
&lt;p&gt;This means the issue affects not only public-key encryption/decrypti…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/emmansun/gmsm&lt;/p&gt;
&lt;p&gt;## Overview&lt;/p&gt;
&lt;p&gt;The current SM9 decryption implementation contains an infinity-point ciphertext forgery vulnerability. The root cause is that, during decryption, the elliptic-curve point C1 in the ciphertext is only deserialized and checked to be on the curve, but the implementation does not explicitly reject the point at infinity.&lt;/p&gt;
&lt;p&gt;In the current implementation, an attacker can construct C1 as the point at infinity, causing the bilinear pairing result to degenerate into the identity element in the GT group. As a result, a critical part of the key derivation input becomes a predictable constant. An attacker who only knows the target user&amp;#39;s UID can derive the decryption key material and then forge a ciphertext that passes the integrity check.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;The direct impact of this vulnerability is ciphertext forgery, not confidentiality loss.&lt;/p&gt;
&lt;p&gt;- The attacker does not need the master public key, the user&amp;#39;s private key, or any other secret material.
- The attacker only needs to know the target UID to construct a seemingly valid ciphertext.
- When the recipient invokes the SM9 decryption API, the forged ciphertext decrypts successfully to attacker-chosen plaintext.
- The C3 integrity check also passes, so this is not merely a format bypass, but a full forgery.&lt;/p&gt;
&lt;p&gt;This issue affects the following paths because they all eventually enter the same `UnwrapKey` logic:&lt;/p&gt;
&lt;p&gt;- `sm9.Decrypt`
- `sm9.DecryptASN1`
- `sm9.UnwrapKey`&lt;/p&gt;
&lt;p&gt;This means the issue affects not only public-key encryption/decrypti…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5xxp-2vrj-x855</guid>
    </item>
  </channel>
</rss>
