๐Ÿ” CVE Alert

CVE-2026-46669

UNKNOWN 0.0

`openvm-pairing` pairing check missing proper subfield check on scaling factor

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

OpenVM is a performant and modular zkVM framework built for customization and extensibility. Prior to version 1.6.0, the openvm-pairing guest library's try_honest_pairing_check function invokes Theorem 3 of https://eprint.iacr.org/2024/640.pdf but does not check that the scaling factor s is in a proper subfield of Fp12. This allows incorrect results to the pairing check. This issue has been patched in version 1.6.0.

CWE CWE-20
Vendor openvm-org
Product openvm
Published Jun 10, 2026
Stay Ahead of the Next One

Get instant alerts for openvm-org openvm

Be the first to know when new unknown vulnerabilities affecting openvm-org openvm are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

openvm-org / openvm
< 1.6.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/openvm-org/openvm/security/advisories/GHSA-76mq-v757-53gr github.com: https://github.com/openvm-org/openvm/releases/tag/v1.6.0