CVE-2026-32614General

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Go ShangMi (Commercial Cryptography) Library (GMSM) is a cryptographic library that covers the Chinese commercial cryptographic public algorithms SM2/SM3/SM4/SM9/ZUC. Prior to 0.41.1, the current SM9 decryption implementation contains an infinity-point ciphertext forgery vulnerability. The root cause is that, during decryption, the elliptic-curve point C1 in the ciphertext is only deserialized and checked to be on the curve, but the implementation does not explicitly reject the point at infinity. In the current implementation, an attacker can construct C1 as the point at infinity, causing the bilinear pairing result to degenerate into the identity element in the GT group. As a result, a critical part of the key derivation input becomes a predictable constant. An attacker who only knows the target user's UID can derive the decryption key material and then forge a ciphertext that passes the integrity check. This vulnerability is fixed in 0.41.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-13); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-13: 1Mentions · 2026-03-18: 1Patch / Workaround · 2026-03-18: 1Technical Details · 2026-03-18: 103-1303-18
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-131
General1
2026-03-181
Disclosure1
Full discourse2 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical SM9 Infinity-Point Ciphertext Forgery (CVE-2026-32614) has been identified. Implementations of the `SM9` algorithm may be at risk. Monitor vendor advisories for affected systems. #Cryptography #SM9 #InfoSec https://www.pulsepatch.io/posts/cve-2026-32614-sm9-infinity-point-ciphertext-forgery

    Post summary

    The post discloses a new critical vulnerability affecting SM9 implementations, advising readers to watch vendor advisories for updates.

    0000028
    1 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-32614 Go ShangMi (Commercial Cryptography) Library (GMSM) is a cryptographic library that covers the Chinese commercial cryptographic public algorithms SM2/SM3/SM4/SM9/ZUC.… https://www.cve.org/CVERecord?id=CVE-2026-32614

    Post summary

    The text merely references the CVE record and briefly describes the affected cryptographic library without providing technical or exploit information.

    00000164
    56.7K followersView on X

Explore more