CVE-2024-49365 - CVE House
Back to Database
Status published High CVE-2024-49365

tiny-secp256k1 allows for verify() bypass when running in bundled environment

Vulnerability Description

tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior to version 1.1.7, a malicious JSON-stringifyable message can be made passing on verify(), when global Buffer is the buffer package. This affects only environments where require('buffer') is the NPM buffer package. Buffer.isBuffer check can be bypassed, resulting in strange objects being accepted as a message, and those messages could trick verify() into returning false-positive true values. This issue has been patched in version 1.1.7.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-49365

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

tiny-secp256k1
Vulnerable Versions:
< 1.1.7

Timeline

Official Publish: July 1st, 2025
Last Modified: July 1st, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)