Vulnerability record · CVE-2026-4258 · published 17 March 2026
CVE-2026-4258: Bitwiseshiftleft stanford javascript crypto library improper verification of cryptographic signature vulnerability
BBitwiseshiftleft · Stanford Javascript Crypto Library
Versions of the package sjcl before 1.0.9 are vulnerable to Improper Verification of Cryptographic Signature due to missing point-on-curve validation in sjcl.ecc.basicKey.publicKey(). An attacker can recover a victim's ECDH private key by sending crafted off-curve public keys and observing ECDH outputs. The dhJavaEc() function directly returns the raw x-coordinate of the scalar multiplication result (no hashing), providing a plaintext oracle without requiring any decryption feedback.
Description
Versions of the package sjcl before 1.0.9 are vulnerable to Improper Verification of Cryptographic Signature due to missing point-on-curve validation in sjcl.ecc.basicKey.publicKey(). An attacker can recover a victim's ECDH private key by sending crafted off-curve public keys and observing ECDH outputs. The dhJavaEc() function directly returns the raw x-coordinate of the scalar multiplication result (no hashing), providing a plaintext oracle without requiring any decryption feedback.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://gist.github.com/Kr0emer/2560f98edb10b0b34f2438cd63913c47 | ExploitMitigationThird Party Advisory |
| https://github.com/bitwiseshiftleft/sjcl/blob/master/core/ecc.js%23L454-L461 | Broken Link |
| https://github.com/bitwiseshiftleft/sjcl/commit/ee307459972442a17beebc29dc331fffd8aff796 | Patch |
| https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-15751243 | |
| https://security.snyk.io/vuln/SNYK-JS-SJCL-15369617 | ExploitThird Party Advisory |
| https://gist.github.com/Kr0emer/2560f98edb10b0b34f2438cd63913c47 | ExploitMitigationThird Party Advisory |
| https://security.snyk.io/vuln/SNYK-JS-SJCL-15369617 | ExploitThird Party Advisory |
Track CVE-2026-4258 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-4258), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.