Vulnerability Details CVE-2026-46669
OpenVM is a performant and modular zkVM framework built for customization and extensibility. Prior to version 1.6.0, the openvm-pairing guest library's try_honest_pairing_check function invokes Theorem 3 of https://eprint.iacr.org/2024/640.pdf but does not check that the scaling factor s is in a proper subfield of Fp12. This allows incorrect results to the pairing check. This issue has been patched in version 1.6.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 19.5%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2026-46669
-
cpe:2.3:a:openvm:openvm:0.1.0
-
cpe:2.3:a:openvm:openvm:0.1.1
-
cpe:2.3:a:openvm:openvm:1.0.0
-
cpe:2.3:a:openvm:openvm:1.0.1
-
cpe:2.3:a:openvm:openvm:1.1.0
-
cpe:2.3:a:openvm:openvm:1.1.1
-
cpe:2.3:a:openvm:openvm:1.1.2
-
cpe:2.3:a:openvm:openvm:1.2.0
-
cpe:2.3:a:openvm:openvm:1.2.1
-
cpe:2.3:a:openvm:openvm:1.3.0
-
cpe:2.3:a:openvm:openvm:1.4.0
-
cpe:2.3:a:openvm:openvm:1.4.1
-
cpe:2.3:a:openvm:openvm:1.4.2
-
cpe:2.3:a:openvm:openvm:1.4.3
-
cpe:2.3:a:openvm:openvm:1.5.0