CVE-2020-36843
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Mar 13, 2025
CWE ID 347
Summary
CVE-2020-36843 affects the EdDSA implementation in EdDSA-Java, version 0.3.0 and below. This vulnerability allows signature malleability, meaning attackers can create new valid signatures for previously used messages that differ from the initial signatures. This breach of the Strong Existential Unforgeability under Chosen Message Attacks (SUF-CMA) property poses a significant risk to security applications relying on EdDSA-Java for signature verification.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.