CVE-2022-50237 Information

Description

The ed25519-dalek crate before 2 for Rust allows a double public key signing function oracle attack. The Keypair implementation leads to a simple computation for extracting a private key.

Reference

https://crates.io/crates/ed25519-dalek https://github.com/MystenLabs/ed25519-unsafe-libs https://rustsec.org/advisories/RUSTSEC-2022-0093.html

CNNVD-202507-3470 (Published: 2025-07-28)

Share on: