CVE-2025-66017
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-11-25

Last updated on: 2025-11-25

Assigner: GitHub, Inc.

Description
CGGMP24 is a state-of-art ECDSA TSS protocol that supports 1-round signing (requires 3 preprocessing rounds), identifiable abort, and a key refresh protocol. In versions 0.6.3 and prior of cggmp21 and version 0.7.0-alpha.1 of cggmp24, presignatures can be used in the way that significantly reduces security. cggmp24 version 0.7.0-alpha.2 release contains API changes that make it impossible to use presignatures in contexts in which it reduces security.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-11-25
Last Modified
2025-11-25
Generated
2026-06-16
AI Q&A
2025-11-25
EPSS Evaluated
2026-06-15
NVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
cggmp24 cggmp24 0.7.0-alpha.2
cggmp21 cggmp21 0.6.3
cggmp24 cggmp24 0.7.0-alpha.1
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-327 The product uses a broken or risky cryptographic algorithm or protocol.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The vulnerability exists in versions 0.6.3 and prior of cggmp21 and version 0.7.0-alpha.1 of cggmp24, where presignatures can be used in a way that significantly reduces security in the CGGMP24 ECDSA TSS protocol. This protocol supports 1-round signing with preprocessing rounds, identifiable abort, and key refresh. The issue is addressed in cggmp24 version 0.7.0-alpha.2 by API changes that prevent insecure use of presignatures.

Impact Analysis

This vulnerability can significantly reduce the security of the signing process in affected versions of the CGGMP24 protocol, potentially allowing attackers to exploit presignatures to compromise cryptographic operations, which may lead to unauthorized actions or data breaches.

Mitigation Strategies

Upgrade to cggmp24 version 0.7.0-alpha.2 or later, as this version contains API changes that prevent the insecure use of presignatures which significantly reduces security.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-66017. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart