Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/cloudflare/circl
  4. ›
  5. CVE-2026-1229

CVE-2026-1229: CIRCL has an incorrect calculation in secp384r1 CombinedMult

February 25, 2026

The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signing relying on this curve are not affected.

The bug was fixed in v1.6.3.

References

  • github.com/advisories/GHSA-q9hv-hpm4-hj6x
  • github.com/cloudflare/circl
  • github.com/cloudflare/circl/pull/583
  • github.com/cloudflare/circl/releases/tag/v1.6.3
  • github.com/cloudflare/circl/security/advisories/GHSA-q9hv-hpm4-hj6x
  • nvd.nist.gov/vuln/detail/CVE-2026-1229

Code Behaviors & Features

Detect and mitigate CVE-2026-1229 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.6.3

Fixed versions

  • 1.6.3

Solution

Upgrade to version 1.6.3 or above.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L

Learn more about CVSS

Weakness

  • CWE-682: Incorrect Calculation

Source file

go/github.com/cloudflare/circl/CVE-2026-1229.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 24 Mar 2026 12:17:40 +0000.