github.com/consensys/gnark
Go5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/consensys/gnarkpage 1 of 1
- CVE-2023-44378HIGHCVSS 7.1EG 7.1✓ Fixed in 0.9.02023-10-09
gnark is a zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.9.0, for some in-circuit values, it is possible to construct two valid decomposition to bits. In addition to the canonical decomposition of `a`…
- CVE-2024-45039MEDIUMCVSS 6.2EG 6.2✓ Fixed in 0.11.02024-09-06
gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Versions prior to 0.11.0 have a soundness issue - in case of multiple commitments used inside the circuit the prover is able to choose all but the last commi…
- CVE-2024-45040MEDIUMCVSS 5.9EG 5.9✓ Fixed in 0.11.02024-09-06
gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.11.0, commitments to private witnesses in Groth16 as implemented break the zero-knowledge property. The vulnerability affects only Groth16…
- CVE-2024-50354MEDIUMCVSS 5.5EG 5.5✓ Fixed in 0.12.02024-10-31
gnark is a fast zk-SNARK library that offers a high-level API to design circuits. In gnark 0.11.0 and earlier, deserialization of Groth16 verification keys allocate excessive memory, consuming a lot of resources and triggering a crash with…
- CVE-2025-57801CRITICALCVSS 9.1EG 9.1✓ Fixed in 0.14.02025-08-22
gnark is a zero-knowledge proof system framework. In versions prior to 0.14.0, the Verify function in eddsa.go and ecdsa.go used the S value from a signature without asserting that 0 ≤ S < order, leading to a signature malleability vulne…
Check whether github.com/consensys/gnark is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/consensys/gnark CVEs against the assets you own.
Start Free Scan →