VDB
KO

RUSTSEC-2026-0240

Ed25519 identity public keys permit universal signature forgery

Details

All published versions of `dcrypt-sign` before 2.0.0 accepted the Edwards identity as an Ed25519 public key. A signature with `R = B` and `S = 1` then verified for every message because the challenge term multiplied the identity. The implementation also admitted other noncanonical or small-order inputs. Consumers that accepted externally supplied dcrypt Ed25519 keys may therefore have accepted forged authorizations.

Version 2.0.0 replaces the custom arithmetic with `ed25519-dalek`, uses strict verification, and rejects noncanonical, small-order, and non-torsion-free public keys and `R` values, as well as noncanonical `S >= L`. No wrapper around the affected verifier is recommended as a complete workaround. Upgrade to 2.0.0 or later, audit registered keys and trust stores, and review historical actions authorized with externally supplied keys.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io / dcrypt-sign
Introduced in: 0.0.0-0 Fixed in: 2.0.0

Upgrade dcrypt-sign to 2.0.0 or newer (ecosystem crates.io).

References