CVE-2019-9155

MEDIUM

Openpgpjs < 4.2.0 - Broken Cryptographic Algorithm

Title source: rule
STIX 2.1

Description

A cryptographic issue in OpenPGP.js <=4.2.0 allows an attacker who is able provide forged messages and gain feedback about whether decryption of these messages succeeded to conduct an invalid curve attack in order to gain the victim's ECDH private key.

Scores

CVSS v3 5.9
EPSS 0.0148
EPSS Percentile 70.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-327
Status published
Products (2)
npm/openpgp 0 - 4.3.0npm
openpgpjs/openpgpjs < 4.2.0
Published Aug 22, 2019
Tracked Since Feb 18, 2026