Top 10 winner
Psychic Signatures in Java
CVE-2022-21449: Psychic Signatures in Java
The Java 15 rewrite of ECDSA verification from C++ into Java dropped the check that signature values r and s are non-zero, so an all-zero signature verifies against any message and any public key. On Java 15 to 18 that forges TLS handshakes, signed JWTs, SAML assertions, OIDC id tokens and WebAuthn assertions (CVE-2022-21449).
Record
- Document
- CVE-2022-21449: Psychic Signatures in Java
- Researcher
- @neilmaddog
- Published by
- Neil Madden
- Date
- Topic
- Server
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of @neilmaddog, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .