CVE-2020-13822: Indutny Elliptic

High severity, CVSS 7.7. EPSS: 2.6% chance of exploitation in the next 30 days.

The Elliptic package 6.5.2 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' bytes, or integer overflows. This could conceivably have a security-relevant impact if an application relied on a single canonical signature.

Affected products

  • Indutny Elliptic: version 6.5.2 only

Published 2020-06-04. Last modified 2026-06-17.