CVE-2026-46669

HIGH

`openvm-pairing` pairing check missing proper subfield check on scaling factor

Title source: cna
STIX 2.1

Description

OpenVM is a performant and modular zkVM framework built for customization and extensibility. Prior to version 1.6.0, the openvm-pairing guest library's try_honest_pairing_check function invokes Theorem 3 of https://eprint.iacr.org/2024/640.pdf but does not check that the scaling factor s is in a proper subfield of Fp12. This allows incorrect results to the pairing check. This issue has been patched in version 1.6.0.

References (2)

Core 2
Core References

Scores

CVSS v3 7.5
EPSS 0.0023
EPSS Percentile 13.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (2)
openvm/openvm < 1.6.0
openvm-org/openvm < 1.6.0
Published Jun 10, 2026
Tracked Since Jun 11, 2026