GHSA-fw7p-63qq-7hpr · Severity: low · Ecosystem: go — filippo.io/edwards25519 MultiScalarMult produces invalid results or undefined behavior if receiver is not the identity
filippo.io/edwards25519 is a Go library implementing the edwards25519 elliptic curve with APIs for building cryptographic primitives. In versions 1.1.0 and earlier, MultiScalarMult produces invalid results or undefined behavior if the receiver is not the identity point. If (*Point).MultiScalarMult is called on an initialized point that is not the identity point, it returns an incorrect result. If the method is called on an uninitialized point, the behavior is undefined. In particular, if the receiver is the zero value, MultiScalarMult returns an invalid point that compares Equal to every other point. Note that MultiScalarMult is a rarely used, advanced API. For example, users who depend on filippo.io/edwards25519 only through github.com/go-sql-driver/mysql are not affected. This issue has been fixed in version 1.1.1.
Conclusion & alert: CVE-2026-26958 is rated Low Risk (17/100): CVSS Low severity, with low exploitation likelihood (EPSS 0.37%). Mandatory action: Low composite risk—no urgent action required; patch on your normal maintenance cycle and revisit priority if CVSS or EPSS increases.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.02% | 0.37% | +0.35% |
| 2 | 2026-03-21 | 0.05% | 0.02% | -0.04% |
| 3 | 2026-02-25 | — | 0.05% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 1.7 | 4.0 | LOW |
|
— | — | [email protected] |
GHSA-fw7p-63qq-7hpr · Severity: low · Ecosystem: go — filippo.io/edwards25519 MultiScalarMult produces invalid results or undefined behavior if receiver is not the identity
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2026-26958 not yet assigned priority: Debian including 1 source packages (golang-filippo-edwards25519), 4 status rows across 4 suites (bookworm, forky, sid, trixie): open 2, resolved 2. | https://security-tracker.debian.org/tracker/CVE-2026-26958 |
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2026-26958 |
suse
|
medium | CVE-2026-26958 severity moderate: SUSE including 22 source package names (cosign-3.0.5-1.1, cosign-3.0.5-150400.3.35.1, …), 62 product×package rows across 40 product lines (Image SL-Micro, Image SL-Micro-Azure, … (40 product lines)): Fixed 46, First Fixed 16. | https://www.suse.com/security/cve/CVE-2026-26958/ |
ubuntu
|
medium | CVE-2026-26958 medium priority: Ubuntu including 1 source packages (golang-filippo-edwards25519), 4 status rows across 4 suites (jammy, noble, questing, upstream): needs-triage 4. | https://ubuntu.com/security/CVE-2026-26958 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||