VDB
Sign up
—

RUSTSEC-2025-0130

Missing check in ZK proof in CGGMP21 Threshold Signing Protocol

Details

Vulnerability concerns a missing check in the ZK proof that enables an attack in which single malicious signer can reconstruct full private key.

### Patches * `cggmp21 v0.6.3` is a patch release that contains a fix that introduces this specific missing check. * However, we recommend upgrading to `cggmp24 v0.7.0-alpha.2` in which we've introduced many other security checks as a precaution. Follow the [migration guidelines](https://github.com/LFDT-Lockness/cggmp21/blob/v0.7.0-alpha.2/CGGMP21_MIGRATION.md) to upgrade.

### References Read our [blog post](https://www.dfns.co/article/cggmp21-vulnerabilities-patched-and-explained) to learn more.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/cggmp24
Introduced in: 0.0.0-0Fixed in: 0.7.0-alpha.2

Upgrade cggmp24 to 0.7.0-alpha.2 or newer (ecosystem crates.io).

References