CVE-2026-55174 Details
Description
UltrafastSecp256k1 is a high-performance, multi-backend secp256k1 engine with reproducible audit evidence, compatibility shims, and profile-based review scopes. Prior to version 4.2.0, UltrafastSecp256k1's ECDSA adaptor pre-signature verification accepts forged adaptor pre-signatures whose "r" value is not cryptographically bound to the adaptor point "T". This issue has been patched in version 4.2.0.
A vulnerability exists in UltrafastSecp256k1 versions prior to 4.2.0, where the ECDSA adaptor pre-signature verification process accepts forged pre-signatures. These forged pre-signatures have an 'r' value that is not properly bound to the adaptor point 'T', allowing a malicious signer to manipulate the signature verification process. This issue arises from a missing DLEQ proof check in the verification path, which is supposed to ensure that the 'r' value is cryptographically tied to the adaptor point. As a result, a pre-signature can be crafted to pass verification while being non-adaptable, breaking the expected soundness of the protocol.
Users should upgrade to UltrafastSecp256k1 version 4.2.1, which addresses this vulnerability by adding the necessary DLEQ proof binding to the ECDSA adaptor pre-signature verification process.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/shrec/UltrafastSecp256k1/security/advisories/GHSA-c7q2-gv3g-rgxm | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/shrec/UltrafastSecp256k1/commit/5478ef566c6af91b48a45c0c61f161f5b1071981 | [email protected] | Source CodeVendor |
| https://github.com/shrec/UltrafastSecp256k1/releases/tag/v4.2.0 | [email protected] | Release NotesVendor |
| https://github.com/shrec/UltrafastSecp256k1/releases/tag/v4.2.1 | [email protected] | Release NotesVendor |
| https://github.com/shrec/UltrafastSecp256k1/security/advisories/GHSA-c7q2-gv3g-rgxm | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-345 | Insufficient Verification of Data Authenticity | [email protected] |
| CWE-347 | Improper Verification of Cryptographic Signature | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| shrec UltrafastSecp256k1 | <= 4.2.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion