The Elliptic package before version 6.5.3 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' bytes, or integer overflows. This could conceivably have a security-relevant impact if an application relied on a single canonical signature.
Upgrade to version 6.5.3 or later.
publishedAdvisory PublishedJul 29th, 2020
reportedReported by UnknownJul 29th, 2020