CVE-2024-49365

HIGH

NPM Tiny-secp256k1 < 1.1.7 - Signature Verification Bypass

Title source: rule
STIX 2.1

Description

tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior to version 1.1.7, a malicious JSON-stringifyable message can be made passing on verify(), when global Buffer is the buffer package. This affects only environments where require('buffer') is the NPM buffer package. Buffer.isBuffer check can be bypassed, resulting in strange objects being accepted as a message, and those messages could trick verify() into returning false-positive true values. This issue has been patched in version 1.1.7.

Scores

CVSS v4 8.1
EPSS 0.0021
EPSS Percentile 43.2%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-347
Status published
Products (2)
bitcoinjs/tiny-secp256k1 < 1.1.7
npm/tiny-secp256k1 0 - 1.1.7npm
Published Jul 01, 2025
Tracked Since Feb 18, 2026