<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 19:03:46 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-66017 — CGGMP21 presignatures can be used in the way that significantly reduces security</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-66017</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; LFDT-Lockness cggmp21&lt;/p&gt;
&lt;p&gt;CGGMP24 is a state-of-art ECDSA TSS protocol that supports 1-round signing (requires 3 preprocessing rounds), identifiable abort, and a key refresh protocol. In versions 0.6.3 and prior of cggmp21 and version 0.7.0-alpha.1 of cggmp24, presignatures can be used in the way that significantly reduces security. cggmp24 version 0.7.0-alpha.2 release contains API changes that make it impossible to use presignatures in contexts in which it reduces security.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; LFDT-Lockness cggmp21&lt;/p&gt;
&lt;p&gt;CGGMP24 is a state-of-art ECDSA TSS protocol that supports 1-round signing (requires 3 preprocessing rounds), identifiable abort, and a key refresh protocol. In versions 0.6.3 and prior of cggmp21 and version 0.7.0-alpha.1 of cggmp24, presignatures can be used in the way that significantly reduces security. cggmp24 version 0.7.0-alpha.2 release contains API changes that make it impossible to use presignatures in contexts in which it reduces security.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-66017</guid>
    </item>
    <item>
      <title>GHSA-8frv-q972-9rq5 — cggmp24 and cggmp21 are vulnerable to signature forgery through altered presignatures</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8frv-q972-9rq5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: cggmp21, crates.io: cggmp24&lt;/p&gt;
&lt;p&gt;### Impact
This attack is against presignatures used in very specific context:
* Presignatures + HD wallets derivation: security level reduces to 85 bits \
  Previously users could generate a presignature, and then choose a HD derivation path while issuing a partial signature via [`Presignature::set_derivation_path`](https://docs.rs/cggmp21/0.6.3/cggmp21/signing/struct.Presignature.html#method.set_derivation_path), which is malleable to attack that reduces target security level. To mitigate, this method has been removed from API.
* Presignatures + &amp;#34;raw signing&amp;#34; (when signer signs a hash without knowing an original message): results into signature forgery attack \
  Previously, users were able to configure [`Presignature::issue_partial_signature`](https://docs.rs/cggmp21/0.6.3/cggmp21/signing/struct.Presignature.html#method.issue_partial_signature) with hashed message without ever providing original mesage. In new API, this method only accepts digests for which original message has been observed.&lt;/p&gt;
&lt;p&gt;### Patches
`cggmp24 v0.7.0-alpha.2` release contains API changes that make it impossible to use presignatures in contexts in which it reduces security. Follow [migration guidelines](https://github.com/LFDT-Lockness/cggmp21/blob/v0.7.0-alpha.2/CGGMP21_MIGRATION.md) to upgrade.&lt;/p&gt;
&lt;p&gt;### Workarounds
Users can continue using un-patched versions of library as long as they don&amp;#39;t use presignatures in said scenarios where it weakens system security. To be sure, migrate to patched version that…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: cggmp21, crates.io: cggmp24&lt;/p&gt;
&lt;p&gt;### Impact
This attack is against presignatures used in very specific context:
* Presignatures + HD wallets derivation: security level reduces to 85 bits \
  Previously users could generate a presignature, and then choose a HD derivation path while issuing a partial signature via [`Presignature::set_derivation_path`](https://docs.rs/cggmp21/0.6.3/cggmp21/signing/struct.Presignature.html#method.set_derivation_path), which is malleable to attack that reduces target security level. To mitigate, this method has been removed from API.
* Presignatures + &amp;#34;raw signing&amp;#34; (when signer signs a hash without knowing an original message): results into signature forgery attack \
  Previously, users were able to configure [`Presignature::issue_partial_signature`](https://docs.rs/cggmp21/0.6.3/cggmp21/signing/struct.Presignature.html#method.issue_partial_signature) with hashed message without ever providing original mesage. In new API, this method only accepts digests for which original message has been observed.&lt;/p&gt;
&lt;p&gt;### Patches
`cggmp24 v0.7.0-alpha.2` release contains API changes that make it impossible to use presignatures in contexts in which it reduces security. Follow [migration guidelines](https://github.com/LFDT-Lockness/cggmp21/blob/v0.7.0-alpha.2/CGGMP21_MIGRATION.md) to upgrade.&lt;/p&gt;
&lt;p&gt;### Workarounds
Users can continue using un-patched versions of library as long as they don&amp;#39;t use presignatures in said scenarios where it weakens system security. To be sure, migrate to patched version that…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8frv-q972-9rq5</guid>
    </item>
  </channel>
</rss>
