RUSTSEC-2026-0240
Ed25519 identity public keys permit universal signature forgery
Details
All published versions of `dcrypt-sign` before 2.0.0 accepted the Edwards identity as an Ed25519 public key. A signature with `R = B` and `S = 1` then verified for every message because the challenge term multiplied the identity. The implementation also admitted other noncanonical or small-order inputs. Consumers that accepted externally supplied dcrypt Ed25519 keys may therefore have accepted forged authorizations.
Version 2.0.0 replaces the custom arithmetic with `ed25519-dalek`, uses strict verification, and rejects noncanonical, small-order, and non-torsion-free public keys and `R` values, as well as noncanonical `S >= L`. No wrapper around the affected verifier is recommended as a complete workaround. Upgrade to 2.0.0 or later, audit registered keys and trust stores, and review historical actions authorized with externally supplied keys.
Are you affected?
Enter the version of the package you're using.
Affected packages
0.0.0-0 Fixed in: 2.0.0 Upgrade dcrypt-sign to 2.0.0 or newer (ecosystem crates.io).
References
- https://crates.io/crates/dcrypt-sign [PACKAGE]
- https://rustsec.org/advisories/RUSTSEC-2026-0240.html [ADVISORY]
- https://github.com/ioi-foundation/dcrypt/security/advisories/GHSA-7j32-2mpw-c784 [ADVISORY]
- https://github.com/ioi-foundation/dcrypt/commit/c99cc86f0ee353010cd202cbcd2c310371b0bbb8 [WEB]
- https://github.com/ioi-foundation/dcrypt/releases/tag/v2.0.0 [WEB]