Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gnark HIGH 7.5
CVE-2025-58157

gnark is a zero-knowledge proof system framework. In version 0.12.0, there is a potential denial of service vulnerability when computing scalar multi…

Patch available
Fix from $1,950 2025-08-29
Gnark CRITICAL 9.1
CVE-2025-57801

gnark is a zero-knowledge proof system framework. In versions prior to 0.14.0, the Verify function in eddsa.go and ecdsa.go used the S value from a s…

Fix: 0.14.0+
Fix from $2,300 2025-08-22
Gnark MEDIUM 5.5
CVE-2024-50354

gnark is a fast zk-SNARK library that offers a high-level API to design circuits. In gnark 0.11.0 and earlier, deserialization of Groth16 verificatio…

Fix: 0.12.0+
Fix from $1,600 2024-10-31
Gnark Crypto MEDIUM 6.2
CVE-2024-45039

gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Versions prior to 0.11.0 have a soundness issue - in case of multip…

Fix: 0.11.0+
Fix from $1,600 2024-09-06
Gnark Crypto MEDIUM 5.9
CVE-2024-45040

gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.11.0, commitments to private witnesses in Groth1…

Fix: 0.11.0+
Fix from $1,600 2024-09-06
Discovery MEDIUM 5.3
CVE-2024-23688

Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session. which should ideally be unique for every message. Th…

Fix: 0.4.5+
Fix from $1,600 2024-01-19
Gnark MEDIUM 5.5
CVE-2023-44378

gnark is a zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.9.0, for some in-circuit values, it is possible to co…

Fix: 0.9.0+
Fix from $1,600 2023-10-09
Gnark Crypto CRITICAL 9.8
CVE-2023-44273

Consensys gnark-crypto through 0.11.2 allows Signature Malleability. This occurs because deserialisation of EdDSA and ECDSA signatures does not ensur…

Fix: 0.12.0+
Fix from $2,300 2023-09-28