Skip to content

BIP322 signature implementation is not fully compliant to the spec

Low
filippos47 published GHSA-xq4h-wqm2-668w Nov 24, 2025

Package

No package listed

Affected versions

<4.1.0

Patched versions

v4.1.0

Description

Summary

The BIP-322 signature verification does not enforce the SIGHASH value to be SIGHASH_ALL, and therefore is not strictly following the spec.

Impact

Non-compliant BIP-322 signatures in proof of possessions can be accepted by the chain.

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs