Skip to main content

CVE-2026-1229

CVE Details

Visit the official vulnerability details page for CVE-2026-1229 to learn more.

Initial Publication

02/24/2026

Last Update

02/24/2026

Third Party Dependency

github.com/cloudflare/circl

NIST CVE Summary

The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signing relying on this curve are not affected.

The bug was fixed in v1.6.3 https://github.com/cloudflare/circl/releases/tag/v1.6.3 .

CVE Severity

0

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Awaiting Analysis

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
1.0.1⚠️ Impacted⚠️ Impacted
0.7.1⚠️ Impacted⚠️ Impacted
0.6.6⚠️ Impacted⚠️ Impacted
0.5.11⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.