CVE-2026-23966: sm-crypto Affected by Private Key Recovery in SM2-PKE
(updated )
A private key recovery vulnerability exists in the SM2 decryption logic of sm-crypto. By interacting with the SM2 decryption interface multiple times, an attacker can fully recover the private key within approximately several hundred interactions.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-23966 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →