CVE-2026-55174: UltrafastSecp256k1: ECDSA adaptor verification accepts non-adaptable pre-signatures due to missing DLEQ binding
UltrafastSecp256k1 is a high-performance, multi-backend secp256k1 engine with reproducible audit evidence, compatibility shims, and profile-based review scopes. Prior to version 4.2.0, UltrafastSecp256k1's ECDSA adaptor pre-signature verification accepts forged adaptor pre-signatures whose "r" value is not cryptographically bound to the adaptor point "T". This issue has been patched in version 4.2.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
UltrafastSecp256k1to a version that resolves this vulnerability.Fixed in 4.2.0
Event History
Frequently Asked Questions
Which deployments are affected?
UltrafastSecp256k1 versions prior to 4.2.0 are affected where ECDSA adaptor pre-signature verification is used. The supplied data does not identify any other affected component or configuration.
What does an attacker need to exploit this issue?
An attacker needs to provide a forged ECDSA adaptor pre-signature with an r value that is not cryptographically bound to the adaptor point T. The vulnerability is remotely reachable, requires no privileges or user interaction, but has high attack complexity.
What is the recommended remediation?
Upgrade UltrafastSecp256k1 to version 4.2.0, which contains the patch. No alternative mitigation is provided in the available data.