CloudflareGHSA-q9hv-hpm4-hj6x
Incorrect calculation in circl secp384r1 CombinedMult
LowCVE-2026-1229 · Published Feb 24, 2026
The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signing relying on this curve are not affected. The bug was fixed in **[v1.6.3](https://github.com/cloudflare/circl/releases/tag/v1.6.3)**.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| circl Product | < 1.6.3 | 1.6.3 |
Details and references
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-682
More Cloudflare advisories
All Cloudflare| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 19 | Use-after-free in connection ID iterator FFI functions | Medium5.6 | 0.29.2 |
| Mar 5 | Cache poisoning via insecure-by-default cache key | High8.4 | 0.8.0 |
| Mar 5 | HTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding Misparsing | Critical9.3 | 0.8.0 |
| Mar 5 | HTTP Request Smuggling via Premature Upgrade | Critical9.3 | 0.8.0 |
| Jan 21 | OS Command Injection in `wrangler pages deploy` | High7.7 | 4.59.1 |
| Nov 42025 | Missing validation of redirect_uri on OAuth callback handler | Medium4.8 | upgradetoversionSHAf7c11c87ef48e9fd898b9d1ebea75078b7279728o... |