{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-22T06:41:17.122","vulnerabilities":[{"cve":{"id":"CVE-2026-22699","sourceIdentifier":"security-advisories@github.com","published":"2026-01-10T06:15:52.377","lastModified":"2026-01-22T14:53:30.840","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for representing various elliptic curve forms, scalars, points, and public/secret keys composed thereof. In versions 0.14.0-pre.0 and 0.14.0-rc.0, a denial-of-service vulnerability exists in the SM2 PKE decryption path where an invalid elliptic-curve point (C1) is decoded and the resulting value is unwrapped without checking. Specifically, AffinePoint::from_encoded_point(&encoded_c1) may return a None/CtOption::None when the supplied coordinates are syntactically valid but do not lie on the SM2 curve. The calling code previously used .unwrap(), causing a panic when presented with such input. This issue has been patched via commit 085b7be."},{"lang":"es","value":"RustCrypto: Curvas Elípticas es soporte de Criptografía de Curva Elíptica (ECC) de propósito general, incluyendo tipos y rasgos para representar varias formas de curvas elípticas, escalares, puntos y claves públicas/secretas compuestas de ellos. En las versiones 0.14.0-pre.0 y 0.14.0-rc.0, existe una vulnerabilidad de denegación de servicio en la ruta de descifrado SM2 PKE donde un punto de curva elíptica (C1) inválido es decodificado y el valor resultante es desempaquetado sin verificación. Específicamente, AffinePoint::from_encoded_point(&amp;encoded_c1) puede devolver un None/CtOption::None cuando las coordenadas proporcionadas son sintácticamente válidas pero no se encuentran en la curva SM2. El código llamador usaba previamente .unwrap(), causando un pánico cuando se le presentaba dicha entrada. Este problema ha sido parcheado a través del commit 085b7be."}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-20"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:rustcrypto:sm2_elliptic_curve:0.14.0:pre0:*:*:*:rust:*:*","matchCriteriaId":"5F5BCFE9-1585-4A90-857F-7F9E1B9C9ADA"},{"vulnerable":true,"criteria":"cpe:2.3:a:rustcrypto:sm2_elliptic_curve:0.14.0:rc0:*:*:*:rust:*:*","matchCriteriaId":"B584C50F-8ED4-45F4-8799-7CCFE8D4DF66"}]}]}],"references":[{"url":"https://github.com/RustCrypto/elliptic-curves/commit/085b7bee647029bd189e1375203418205006bcab","source":"security-advisories@github.com","tags":["Patch"]},{"url":"https://github.com/RustCrypto/elliptic-curves/pull/1602","source":"security-advisories@github.com","tags":["Issue Tracking","Patch"]},{"url":"https://github.com/RustCrypto/elliptic-curves/security/advisories/GHSA-78p6-6878-8mj6","source":"security-advisories@github.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://github.com/RustCrypto/elliptic-curves/security/advisories/GHSA-78p6-6878-8mj6","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Vendor Advisory"]}]}}]}