CVE-2019-20399: Parity LIBSECP256K1

Medium severity, CVSS 5.9. EPSS: 0.9% chance of exploitation in the next 30 days.

A timing vulnerability in the Scalar::check_overflow function in Parity libsecp256k1-rs before 0.3.1 potentially allows an attacker to leak information via a side-channel attack.

Affected products

  • Parity LIBSECP256K1: before 0.3.1 (fixed in 0.3.1)

Published 2020-01-23. Last modified 2026-06-17.