CVE-2026-54872
Received Received - Intake

Timing Side-Channel in OpenSSL ECDSA/SM2 Signature Operations

Vulnerability report for CVE-2026-54872, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: OpenSSL Software Foundation

Description

Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce. The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1. Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue. The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected. FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openssl openssl *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-208 Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a timing side-channel in OpenSSL's elliptic curve scalar multiplication for ECDSA and SM2 signatures. The generic implementation leaks information about the secret nonce through timing variations during operations on curves without dedicated constant-time implementations. Attackers measuring signing times could recover the private key over many signatures using lattice attacks.

Detection Guidance

This vulnerability involves timing side-channel leaks in elliptic curve scalar multiplication. Detection requires measuring signing operation times over many samples to identify timing variations. Use tools like OpenSSL's speed command to benchmark ECDSA/SM2 operations and compare timings across different curves. Focus on Brainpool and generic prime curves.

Impact Analysis

If you use applications relying on ECDSA signing with Brainpool or other generic prime curves, or SM2 signing on platforms using the generic implementation, your cryptographic operations could be vulnerable. An attacker with timing measurements may eventually recover private keys used for signing, compromising confidentiality and authenticity of signed data.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data if private keys are compromised, violating confidentiality requirements in GDPR and HIPAA. Organizations using affected curves must address this to maintain compliance with data protection standards.

Mitigation Strategies

Update OpenSSL to a patched version containing the fix for CVE-2026-54872. Ensure applications use constant-time implementations for ECDSA/SM2 signing. Avoid Brainpool curves and generic prime curves if possible. For FIPS environments, no action is needed as NIST curves are unaffected.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54872. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart