CVE-2022-23806
Go vulnerability analysis and mitigation

Overview

CVE-2022-23806 is a security vulnerability discovered in the crypto/elliptic package of Go programming language affecting versions before 1.16.14 and 1.17.x before 1.17.7. The vulnerability was identified when the IsOnCurve function could incorrectly return true in situations with a big.Int value that is not a valid field element. The vulnerability was disclosed in February 2022 and affects the cryptographic operations in Go's elliptic curve implementation (Golang Announce).

Technical details

The vulnerability exists in the Curve.IsOnCurve function within the crypto/elliptic package. The function can incorrectly validate certain big.Int values that are not valid field elements (negative or overflowing), potentially causing a panic or an invalid curve operation. It's important to note that the Unmarshal function will never return such invalid values. The vulnerability has been assigned a CVSS score of 9.1 (CRITICAL), indicating its high severity (NetApp Advisory).

Impact

If successfully exploited, this vulnerability could lead to invalid cryptographic computations and potential denial-of-service conditions. The incorrect validation of field elements could compromise the security of cryptographic operations that rely on elliptic curve calculations (Debian LTS).

Exploitability

The vulnerability requires network access and has low attack complexity. No authentication or user interaction is required to exploit this vulnerability. While the vulnerability is serious, it's worth noting that the Unmarshal function is not affected and will not return invalid values (NetApp Advisory).

Mitigation and workarounds

The vulnerability has been fixed in Go versions 1.16.14 and 1.17.7. Users are strongly recommended to upgrade to these or later versions. For systems using p224 certificates, it's recommended to avoid using them until the update can be applied (Golang Announce).

Additional resources


SourceThis report was generated using AI

Related Go vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-54365HIGH8.7
  • Go logoGo
  • kubeflow-katib
NoYesJun 23, 2026
CVE-2026-39822HIGH7.8
  • Go logoGo
  • k3s
NoYesJul 08, 2026
CVE-2026-42504HIGH7.5
  • Go logoGo
  • kyverno-policy-reporter
NoYesJun 02, 2026
CVE-2026-42505MEDIUM5.3
  • Go logoGo
  • crossplane-provider-aws-autoscalingplans-fips
NoYesJul 08, 2026
CVE-2026-42507MEDIUM5.3
  • Go logoGo
  • migrate
NoYesJun 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management