RustSec logo

HistoryEditJSON (OSV)

RUSTSEC-2026-0240

Ed25519 identity public keys permit universal signature forgery

Reported
Issued
Package
dcrypt-sign (crates.io)
Type
Vulnerability
Categories
Keywords
#ed25519 #identity-key #signature-forgery
Aliases
References
Patched
  • >=2.0.0

Description

All published versions of dcrypt-sign before 2.0.0 accepted the Edwards identity as an Ed25519 public key. A signature with R = B and S = 1 then verified for every message because the challenge term multiplied the identity. The implementation also admitted other noncanonical or small-order inputs. Consumers that accepted externally supplied dcrypt Ed25519 keys may therefore have accepted forged authorizations.

Version 2.0.0 replaces the custom arithmetic with ed25519-dalek, uses strict verification, and rejects noncanonical, small-order, and non-torsion-free public keys and R values, as well as noncanonical S >= L. No wrapper around the affected verifier is recommended as a complete workaround. Upgrade to 2.0.0 or later, audit registered keys and trust stores, and review historical actions authorized with externally supplied keys.

Advisory available under CC0-1.0 license.