FlawAtlas
Search the atlas
CVE-2026-1229 Low

CIRCL has an incorrect calculation in secp384r1 CombinedMult in github.com/cloudflare/circl

CIRCL has an incorrect calculation in secp384r1 CombinedMult in github.com/cloudflare/circl

Exploit probability 0.4%
Published February 27, 2026
Required by Not available
Last source change March 9, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

1 explicit affected versions

Go github.com/cloudflare/circl
Go github.com/cloudflare/circl

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities GHSA-q9hv-hpm4-hj6x

The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signing relying on this curve are not affected. The bug was fixed in **[v1.6.3](https://github.com/cloudflare/circl/releases/tag/v1.6.3)**.

View original source
Open Source Vulnerabilities GO-2026-4550

CIRCL has an incorrect calculation in secp384r1 CombinedMult in github.com/cloudflare/circl

View original source
Open Source Vulnerabilities CVE-2026-1229

The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signing relying on this curve are not affected. The bug was fixed in v1.6.3 https://github.com/cloudflare/circl/releases/tag/v1.6.3 .

View original source

05 / REFERENCES

Further evidence