Skip to content
CloudflareGHSA-q9hv-hpm4-hj6x

Incorrect calculation in circl secp384r1 CombinedMult

LowCVE-2026-1229 · Published Feb 24, 2026

The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signing relying on this curve are not affected. The bug was fixed in **[v1.6.3](https://github.com/cloudflare/circl/releases/tag/v1.6.3)**.

GitHub advisory

Affected versions

PackageAffectedFixed in
circl
Product
< 1.6.31.6.3
Details and references

More Cloudflare advisories

All Cloudflare
Advisory
Use-after-free in connection ID iterator FFI functions
Medium5.6Jun 19
Cache poisoning via insecure-by-default cache key
High8.4Mar 5
HTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding Misparsing
Critical9.3Mar 5
HTTP Request Smuggling via Premature Upgrade
Critical9.3Mar 5
OS Command Injection in `wrangler pages deploy`
High7.7Jan 21
Missing validation of redirect_uri on OAuth callback handler
Medium4.8Nov 4, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.