CVE-2026-1229
Packer vulnerability analysis and mitigation

Overview

CVE-2026-1229 is an incorrect cryptographic calculation vulnerability in the CombinedMult function of Cloudflare's CIRCL library (github.com/cloudflare/circl/ecc/p384), affecting the secp384r1 elliptic curve. The function produces incorrect output for specific inputs due to the use of incomplete addition formulas. All CIRCL versions prior to 1.6.3 are affected. The vulnerability was published on February 24, 2026, and fixed in CIRCL v1.6.3. It carries a CVSS v4.0 base score of 2.9 (Low) and a CVSS v3.1 base score of 9.8 (Critical, reflecting a worst-case theoretical assessment) (Github Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-682 (Incorrect Calculation), with a secondary estimate of CWE-190 (Integer Overflow or Wraparound). The CombinedMult function in the ecc/p384 package uses incomplete elliptic curve point addition formulas that fail to handle certain degenerate input cases (e.g., point doubling or the point at infinity), producing mathematically incorrect results for those specific inputs. The fix, applied in v1.6.3, replaces the incomplete formulas with complete addition formulas that correctly handle all input cases. Notably, standard ECDH key exchange and ECDSA signing operations — which use different internal code paths — are not affected by this bug. The vulnerability was credited to researcher guidovranken (Github Advisory, CIRCL Repository).

Impact

The primary impact is on the integrity of cryptographic operations that directly invoke the CombinedMult function on the secp384r1 curve, such as certain signature verification or multi-scalar multiplication use cases. Incorrect point multiplication results could cause cryptographic protocols relying on this function to produce wrong outputs, potentially enabling signature forgery or protocol-level integrity failures in affected applications. However, the practical impact is limited: ECDH and ECDSA signing are explicitly unaffected, and exploitation requires crafting specific inputs that trigger the faulty code path, making real-world impact low for most deployments (Github Advisory, Red Hat Bugzilla).

Exploitability

There is no evidence of active in-the-wild exploitation or a public proof-of-concept exploit as of the time of reporting (Github Advisory). The EPSS score is approximately 0.013–0.026%, placing it in a low percentile for near-term exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The CVSS v4.0 exploit maturity is rated "Proof of Concept" in the Feedly data, though no public PoC has been confirmed. No threat actor attribution has been reported (Feedly).

Mitigation and workarounds

The fix is available in CIRCL v1.6.3, released January 22, 2026. Organizations should upgrade the github.com/cloudflare/circl Go module to v1.6.3 or later. Downstream projects that bundle CIRCL — including HashiCorp Vault, Pulumi Kubernetes provider, DataDog Agent, Portainer, rclone, and CircleCI Server — have released or are releasing updated versions incorporating the fix. Given the low severity and absence of known exploitation, this can be addressed within normal patching cycles. Applications that do not use the CombinedMult function directly (i.e., only use standard ECDH or ECDSA) have minimal risk exposure (Github Advisory, CIRCL Repository).

Community reactions

The vulnerability was assigned by Cloudflare and disclosed via the GitHub Advisory Database (GHSA-q9hv-hpm4-hj6x). Red Hat tracked it via Bugzilla with a low priority/severity rating. The ENISA European Vulnerability Database (EUVD-2026-7384) also catalogued the issue. Community reaction has been muted given the low practical impact; the vulnerability was noted on Bluesky and various CVE aggregator feeds but generated no significant security community controversy. Multiple downstream vendors (HashiCorp, DataDog, Portainer, rclone, CircleCI) have proactively issued updated releases incorporating the CIRCL fix (Github Advisory, Red Hat Bugzilla).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Ubuntu

Unknown

devel

golang-github-cloudflare-circl

Unknown

jammy

golang-github-cloudflare-circl

Unknown

jammy (esm-apps)

golang-github-cloudflare-circl

Unknown

noble

golang-github-cloudflare-circl

Unknown

noble (esm-apps)

golang-github-cloudflare-circl

Unknown

resolute

golang-github-cloudflare-circl

Unknown

resolute (esm-apps)

golang-github-cloudflare-circl

Unknown

Alpine

Fixed

edge

rclone: 1.73.5-r0

Fixed

SourceThis report was generated using AI

Related Packer vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-84304HIGH8.7
  • cAdvisor logocAdvisor
  • envoy-gateway-fips-1.8
NoYesSep 01, 2026
CVE-2026-78662HIGH7.5
  • Docker logoDocker
  • kubescape-server-fips
NoYesSep 02, 2026
CVE-2026-56855HIGH7.5
  • Docker logoDocker
  • fulcio-fips
NoYesSep 02, 2026
CVE-2026-19589HIGH7.1
  • Packer logoPacker
  • cpe:2.3:a:hashicorp:packer
NoYesAug 17, 2026
CVE-2026-71557MEDIUM6.3
  • Packer logoPacker
  • kyverno-fips-1.17
NoYesAug 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management