CVE-2026-77696
CVE Details
Visit the official vulnerability details page for CVE-2026-77696 to learn more.
Initial Publication
09/29/2026
Last Update
09/29/2026
Third Party Dependency
openssl-libs
NIST CVE Summary
Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel.
Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key.
CWE: CWE-208: Observable Timing Discrepancy
Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel.
Applications performing SM2 signature generation are affected on all platforms.
FIPS Impact: no SM2 is not a FIPS algorithm.
CVE Severity
Our Official Summary
Investigation is ongoing to determine how this vulnerability affects our products.
Status
Awaiting Analysis
Affected Products & Versions
| Version | PaletteAI | PaletteAI VerteX |
|---|---|---|
| 1.4.0 | ⚠️ Impacted | ⚠️ Impacted |
| 1.3.2 | ⚠️ Impacted | ⚠️ Impacted |
| 1.2.2 | ⚠️ Impacted | ⚠️ Impacted |
Revision History
No revisions available.