Showing 1 vulnerability on this page for frost

Signals CISA KEV Ransomware Nuclei
ZcashFoundation vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

frost-core: refresh shares with smaller min_signers will reduce group security

ZF FROST is a Rust implementation of FROST (Flexible Round-Optimised Schnorr Threshold signatures). In versions 2.0.0 through 2.1.0, refresh shares with smaller min_signers will reduce security of group. The inability to change min_signers (i.e. the threshold) with the refresh share functionality (frost_core::keys::refresh module) was not made clear to users. Using a smaller value would not decrease the threshold, and attempts to sign using a smaller threshold would fail. Additionally, after ref

CWE-269CWE-325Sep 4, 2025
CVSS6.0v4.0EPSS0.286%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX