Uncaught Exception Affecting std/crypto/elliptic package, versions <1.17.9>=1.18.0-0 <1.18.1


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
4.2% (90th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-STDCRYPTOELLIPTIC-14564697
  • published6 Jan 2026
  • disclosed20 May 2022
  • creditProject Wycheproof

Introduced: 20 May 2022

CVE-2022-28327  (opens in a new tab)
CWE-248  (opens in a new tab)

How to fix?

Upgrade std/crypto/elliptic to version 1.17.9, 1.18.1 or higher.

Overview

std/crypto/elliptic is a Go standard library package std/crypto/elliptic

Affected versions of this package are vulnerable to Uncaught Exception.

Go Vulnerability Report:
via the P256().ScalarMult or P256().ScalarBaseMult functions when provided with a crafted scalar input longer than 32 bytes. An attacker can cause a panic and potentially disrupt service by supplying such an input. This is only exploitable if the architecture is not amd64, arm64, ppc64le, or s390x.

CVSS Base Scores

version 4.0
version 3.1