CVE-2020-36843

MEDIUM

EdDSA-Java <0.3.0 - Signature Malleability

Title source: llm
STIX 2.1

Description

The implementation of EdDSA in EdDSA-Java (aka ed25519-java) through 0.3.0 exhibits signature malleability and does not satisfy the SUF-CMA (Strong Existential Unforgeability under Chosen Message Attacks) property. This allows attackers to create new valid signatures different from previous signatures for a known message.

References (2)

Core 2

Scores

CVSS v3 4.3
EPSS 0.0013
EPSS Percentile 3.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-347
Status published
Products (3)
net.i2p/i2p 0 - 0.9.39Maven
net.i2p.crypto/eddsa 0Maven
str4d/ed25519-java < 0.3.0
Published Mar 13, 2025
Tracked Since Feb 18, 2026