An open index of dependabot pull requests across open source projects.

elliptic

Ecosystem:
npm
Package URL:
pkg:npm/elliptic
Total PRs:
6,241 Dependabot PRs
Latest PR:
13 days ago
Unique Repositories:
5,340 repositories
Unique Repos (30 days):
2 repositories
Security Advisories
Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string)
GHSA-vjh7-7g9h-fjfh CRITICAL published over 1 year ago • updated about 2 months ago
### Summary Private key can be extracted from ECDSA signature upon signing a malformed input (e.g. a string or a number), which could e.g. come fr...
Elliptic allows BER-encoded signatures
GHSA-49q7-c7j4-3p7m CVE-2024-42461 LOW published almost 2 years ago • updated 10 days ago
In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.
Elliptic's verify function omits uniqueness validation
GHSA-434g-2637-qmqr CVE-2024-48949 LOW published over 1 year ago • updated 24 days ago
The Elliptic package 6.5.5 for Node.js for EDDSA implementation does not perform the required check if the signature proof(s) is within the bounds ...
Elliptic Uses a Cryptographic Primitive with a Risky Implementation
GHSA-848j-6mx2-7j84 CVE-2025-14505 LOW published 5 months ago • updated 20 days ago
The ECDSA implementation of the Elliptic package generates incorrect signatures if an interim value of 'k' (as computed based on step 3.2 of RFC 6...
Elliptic Uses a Broken or Risky Cryptographic Algorithm
GHSA-r9p9-mrjm-926w CVE-2020-28498 MODERATE published about 5 years ago • updated about 5 hours ago
The npm package `elliptic` before version 6.5.4 are vulnerable to Cryptographic Issues via the secp256k1 implementation in elliptic/ec/key.js. Ther...
Recent PRs (filtered by: Patch PRs )
Bump elliptic from 6.6.0 to 6.6.1

ooni/run #222

6.6.0 → 6.6.1 Patch PR
Closed 6 months ago 1 comment
ooni
Package Details
Name: elliptic
Ecosystem: npm
PURL Type: npm
Package URL: pkg:npm/elliptic
JSON API: View JSON
Security Advisories

9

Active advisories
CRITICAL 1
HIGH 1
MODERATE 1
LOW 6
View All npm Advisories
Package Information
Description:

EC cryptography

Repository: https://github.com/indutny/elliptic
Homepage: https://github.com/indutny/elliptic
Latest Release: 6.6.1
over 1 year ago
Dependent Repos: 667,005
Dependent Packages: 2,976
Downloads: 53,852,887
Ranking: Top 0.0451% by dependent repos Top 0.0363% by downloads Top 0.0275% by dependent pkgs
PR Status
Open 2,995 (48.0%)
Merged 911 (14.6%)
Closed 1,942 (31.1%)
PR Types
Minor 4,351 (69.7%)
Patch 1,392 (22.3%)
Removal 86 (1.4%)