CVE-2025-66016: CGGMP24 is missing a check in the ZK proof used in CGGMP21

Published Nov 25, 2025
·
Updated

Impact cggmp21 concerns a missing check in the ZK proof that enables an attack in which a single malicious signer can reconstruct full private key.

Patches cggmp21 v0.6.3 is a patch release that contains a fix that introduces this specific missing check However, cggmp21 recommends upgrading to cggmp24 v0.7.0-alpha.2 which contains many other security checks as a precaution. Follow migration guideline to upgrade.

Workarounds Update to cggmp21 v0.6.3, a minor release that contains a minimal security patch.

However, for full mitigation, users will need to upgrade to cggmp24 v0.7.0-alpha.2 as it contains many more security check implementations.

Resources Read this blog post to learn more.

Other sources

CGGMP24 is a state-of-art ECDSA TSS protocol that supports 1-round signing (requires 3 preprocessing rounds), identifiable abort, and a key refresh protocol. Prior to version 0.6.3, there is a missing check in the ZK proof that enables an attack in which single malicious signer can reconstruct full private key. This issue has been patched in version 0.6.3, for full mitigation it is recommended to upgrade to cggmp24 version 0.7.0-alpha.2 as it contains more security checks.

MITRE

Affected Software

2 affected componentsFixes available
rust/cggmp24<0.7.0-alpha.2
0.7.0-alpha.2
rust/cggmp21<0.6.3
0.6.3

Event History

Nov 25, 2025
CVE Published
via MITRE·07:48 PM
Data Sourced
via MITRE·07:48 PM
DescriptionWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·08:41 PM
Data Sourced
via GitHub·08:41 PM
DescriptionWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-66016?

CVE-2025-66016 is considered a critical vulnerability due to the ability of a malicious signer to reconstruct a full private key.

2

How do I fix CVE-2025-66016?

To fix CVE-2025-66016, update to cggmp21 version 0.6.3 or later, specifically cggmp24 version 0.7.0-alpha.2.

3

What is the specific impact of CVE-2025-66016?

CVE-2025-66016 allows an attacker to exploit a missing check in the ZK proof to reconstruct a full private key.

4

Which software versions are affected by CVE-2025-66016?

CVE-2025-66016 affects cggmp21 versions prior to 0.6.3 and cggmp24 versions prior to 0.7.0-alpha.2.

5

Who should prioritize addressing CVE-2025-66016?

Organizations using the vulnerable versions of cggmp21 and cggmp24 should prioritize addressing CVE-2025-66016 to protect against key reconstruction attacks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203