CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.1. See the original NVD description below for full technical details.
CVE
CVE-2022-23806
Severity
CRITICAL
CVSS
9.1
EPSS
3.10%
Original NVD Description
Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.
Related CVEs
Other vulnerabilities affecting the same vendor(s)