CVE-2026-4258Disclosure(bitwiseshiftleft / stanford_javascript_crypto_library)

LOWCVSS 7.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Versions of the package sjcl before 1.0.9 are vulnerable to Improper Verification of Cryptographic Signature due to missing point-on-curve validation in sjcl.ecc.basicKey.publicKey(). An attacker can recover a victim's ECDH private key by sending crafted off-curve public keys and observing ECDH outputs. The dhJavaEc() function directly returns the raw x-coordinate of the scalar multiplication result (no hashing), providing a plaintext oracle without requiring any decryption feedback.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347CWE-325

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • stanford_javascript_crypto_library

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-03-17); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Products
stanford_javascript_crypto_library

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-17: 4Mentions · 2026-03-25: 1Technical Details · 2026-03-17: 3Technical Details · 2026-03-25: 103-1703-25
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-174
Disclosure3General1
2026-03-251
Disclosure1
Full discourse5 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    Missing point-on-curve validation in `sjcl.ecc.basicKey.publicKey` (CVE-2026-4258) could weaken cryptographic operations. Review your `sjcl` implementations. #cryptography #infosec #javascript https://www.pulsepatch.io/posts/cve-2026-4258-sjcl-ecc-point-validation

    Post summary

    The post highlights a missing ECC point validation in the SJCL library that could weaken security and urges users to review their implementations, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000041
    2 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4258 All versions of the package sjcl are vulnerable to Improper Verification of Cryptographic Signature due to missing point-on-curve validation in sjcl.ecc.basicKey.public… https://www.cve.org/CVERecord?id=CVE-2026-4258

    Post summary

    The text announces CVE-2026-4258, noting an improper verification of cryptographic signatures in the sjcl library due to missing point‑on‑curve validation.

    00000150
    56.7K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-4258 📊 Severity: 7.5 🚨 Risk Level: High 🧩 Affects: Oracle Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4258 #CVE-2026-4258 #CVE #High #Oracle #CyberSecurity #InfoSec https://t.co/dexK9pqzGG

    Post summary

    The tweet is simply an alert announcing CVE‑2026‑4258 with its severity score, risk level, and affected vendor, linking to the NVD entry.

    0000058
    101 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4258 - Apache Sjcl ECDSA Signature Verification Vulnerability Intel Report: https://ift.tt/xcbXa4e

    Post summary

    The post announces CVE-2026-4258, an ECDSA signature verification vulnerability in Apache Sjcl, and links to an intel report for more details.

    0000048
    336 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-4258 Cryptographic Signature Vulnerability in sjcl Enabling ECDH Private Key Recovery https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4258

    Post summary

    A concise bulletin announcing CVE‑2026‑4258, highlighting a cryptographic signature flaw in sjcl that could allow ECDH private key recovery, without details on exploitation or remediation.

    0000056
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbitwiseshiftleftstanford_javascript_crypto_library-node.js-

Explore more