CVE-2024-49365 HIGH

CVE-2024-49365: tiny-secp256k1 allows for verify() bypass when running in bundled environment

Vendor Bitcoinjs
Product tiny-secp256k1
Weakness CWE-347
Published July 1, 2025
Last update July 1, 2025

CVSS base score

8.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior to version 1.1.7, a malicious JSON-stringifyable message can be made passing on verify(), when global Buffer is the buffer package. This affects only environments where require('buffer') is the NPM buffer package. Buffer.isBuffer check can be bypassed, resulting in strange objects being accepted as a message, and those messages could trick verify() into returning false-positive true values. This issue has been patched in version 1.1.7.

Key dates

02Disclosure timeline

July 1, 2025 CVE published
July 1, 2025 Record updated