| - module: github.com/consensys/gnark |
| vulnerable_at: 0.9.0-alpha |
| - package: github.com/consensys/gnark/frontend/cs/r1cs |
| - builder.AssertIsLessOrEqual |
| - builder.mustBeLessOrEqVar |
| - builder.mustBeLessOrEqCst |
| - package: github.com/consensys/gnark/frontend/cs/scs |
| - builder.AssertIsLessOrEqual |
| - builder.mustBeLessOrEqVar |
| - builder.mustBeLessOrEqCst |
| - package: github.com/consensys/gnark/internal/backend/circuits |
| - package: github.com/consensys/gnark/std/math/bits |
| summary: Unsoundness in variable comparison / non-unique binary decomposition in github.com/consensys/gnark |
| - report: https://github.com/zkopru-network/zkopru/issues/116 |
| - fix: https://github.com/Consensys/gnark/pull/835 |
| - fix: https://github.com/Consensys/gnark/commit/59a4087261a6c73f13e80d695c17b398c3d0934f |
| - advisory: https://github.com/advisories/GHSA-498w-5j49-vqjg |