CVE-2022-50237: Dalek-Cryptography ED25519-Dalek
Medium severity, CVSS 5.9. EPSS: 0.2% chance of exploitation in the next 30 days.
The ed25519-dalek crate before 2 for Rust allows a double public key signing function oracle attack. The Keypair implementation leads to a simple computation for extracting a private key.
Affected products
- Dalek-Cryptography ED25519-Dalek: before 2 (fixed in 2)
Published 2025-07-28. Last modified 2026-06-17.