目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-73567— sm-crypto: Node.js 中 SM2 密钥生成可预测漏洞

CVSS 9.1 · Critical EPSS 0.32% · P25

Affected Version Matrix 1

ベンダープロダクトVersion Rangeステータス
JuneAndGreensm-crypto< 0.5.0affected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-73567の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock
ソース: CVE Program / CVE List V5
脆弱性説明
sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0, the default no-argument sm2.generateKeyPairHex() path in Node.js uses the module-wide SecureRandom instance in src/sm2/utils.js, supplied by jsbn@1.1.0, which seeds an ARC4 stream from Math.random() and new Date().getTime() because window.crypto.getRandomValues is unavailable even though globalThis.crypto exists. An attacker who can observe the process's Math.random() outputs and estimate the key-generation time can reconstruct the seed, recover generated SM2 private keys, and predict signing ephemeral scalars used to forge signatures. This issue is fixed in version 0.5.0.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
ソース: CVE Program / CVE List V5
脆弱性タイプ
使用具有密码学弱点缺陷的PRNG
ソース: CVE Program / CVE List V5

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
JuneAndGreensm-crypto < 0.5.0 -

II. CVE-2026-73567の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム
Qwen3.6-35B-A3B · 6578 文字数
Pro+限定の内容:
脆弱性再現の録画(実際のサンドボックス構築 + トリガー、限定)
脆弱性の原理を深く分析
トリガー条件と影響範囲
完全な実行可能POCコード
攻撃チェーンと緩和策の提案
POCパッケージのダウンロード
月間100件以上のAI生成枠

III. CVE-2026-73567のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-73567 补丁与修复 (1)

CVE-2026-73567 厂商安全公告 (1)

IV. 関連脆弱性

V. CVE-2026-73567へのコメント

まだコメントはありません


コメントを残す