Wycheproof
Wycheproof is an extensive collection of test vectors designed to verify the correctness of cryptographic implementations and test against known attacks. Originally developed by Google, it is now a community-managed project where contributors can add test vectors for specific cryptographic constructions.
Background
Key Concepts
Why This Matters
Cryptographic implementations are notoriously difficult to get right. Even small bugs can:
- Expose private keys
- Allow signature forgery
- Enable message decryption
- Create consensus problems when different implementations accept/reject the same inputs
Wycheproof has found vulnerabilities in major libraries including OpenJDK's SHA1withDSA, Bouncy Castle's ECDHC, and the elliptic npm package.
When to Use
Apply Wycheproof when:
- Testing cryptographic implementations (AES-GCM, ECDSA, ECDH, RSA, etc.)
- Validating that crypto code handles edge cases correctly
- Verifying implementations against known attack vectors
- Setting up CI/CD for cryptographic libraries
- Auditing third-party crypto code for correctness
Consider alternatives when:
- Testing for timing side-channels (use constant-time testing tools instead)
- Finding new unknown bugs (use fuzzing instead)
- Testing custom/experimental cryptographic algorithms (Wycheproof only covers established algorithms)
Quick Reference
Testing Workflow
Repository Structure
The Wycheproof repository is organized as follows:
The essential folders are testvectors and testvectors_v1. While both contain similar files, testvectors_v1 includes more detailed information and is recommended for new integrations.
Supported Algorithms
Wycheproof provides test vectors for a wide range of cryptographic algorithms:
Test File Structure
Each JSON test file tests a specific cryptographic construction. All test files share common attributes:
Test Groups
Test groups group sets of tests based on shared attributes such as:
- Key sizes
- IV sizes
- Public keys
- Curves
This classification allows extracting tests that meet specific criteria relevant to the construction being tested.
Test Vector Attributes
Shared Attributes
All test vectors contain four common fields:
- tcId: Unique identifier for the test vector within a file
- comment: Additional information about the test case
- flags: Descriptions of specific test case types and potential dangers (referenced in
notesfield) - result: Expected outcome of the test
The result field can take three values:
Unique Attributes
Unique attributes are specific to the algorithm being tested:
Implementation Guide
Phase 1: Add Wycheproof to Your Project
Option 1: Git Submodule (Recommended)
Adding Wycheproof as a git submodule ensures automatic updates:
Option 2: Fetch Specific Test Vectors
If submodules aren't possible, fetch specific JSON files:
Phase 2: Parse Test Vectors
Identify the test file for your algorithm and parse the JSON:
Python Example:
JavaScript Example:
Phase 3: Write Testing Harness
Create test functions that handle both valid and invalid test cases.
Python/pytest Example:
JavaScript/Mocha Example:
Phase 4: CI Integration
Ensure test vectors stay up to date by:
- Using git submodules: Update submodule in CI before running tests
- Fetching latest vectors: Run fetch script before test execution
- Scheduled updates: Set up weekly/monthly updates to catch new test vectors
Common Vulnerabilities Detected
Wycheproof test vectors are designed to catch specific vulnerability patterns:
Signature Malleability: Deep Dive
Problem: Implementations that don't validate signature encoding can accept multiple valid signatures for the same message.
Example (EdDSA): Appending or removing zeros from signature:
How to detect:
Impact: Can lead to consensus problems when different implementations accept/reject the same signatures.
Related Wycheproof tests:
- EdDSA: tcId 37 - "removing 0 byte from signature"
- ECDSA: tcId 06 - "Legacy: ASN encoding of r misses leading 0"
Case Study: Elliptic npm Package
This case study demonstrates how Wycheproof found three CVEs in the popular elliptic npm package (3000+ dependents, millions of weekly downloads).
Overview
The elliptic library is an elliptic-curve cryptography library written in JavaScript, supporting ECDH, ECDSA, and EdDSA. Using Wycheproof test vectors on version 6.5.6 revealed multiple vulnerabilities:
- CVE-2024-42459: EdDSA signature malleability (appending/removing zeros)
- CVE-2024-42460: ECDSA DER encoding - invalid bit placement
- CVE-2024-42461: ECDSA DER encoding - leading zero in length field
Methodology
- Identify supported curves: ed25519 for EdDSA
- Find test vectors:
testvectors_v1/ed25519_test.json - Parse test vectors: Load JSON and extract tests
- Write test harness: Create parameterized tests
- Run tests: Identify failures
- Analyze root causes: Examine implementation code
- Propose fixes: Add validation checks
Key Findings
EdDSA Issue (CVE-2024-42459):
- Missing signature length validation
- Allowed trailing zeros in signatures
- Fix: Add
if(sig.length !== 128) return false;
ECDSA Issue 1 (CVE-2024-42460):
- Missing check for first bit being zero in DER-encoded r and s values
- Fix: Add
if ((data[p.place] & 128) !== 0) return false;
ECDSA Issue 2 (CVE-2024-42461):
- DER length field accepted leading zeros
- Fix: Add
if(buf[p.place] === 0x00) return false;
Impact
All three vulnerabilities allowed multiple valid signatures for a single message, leading to consensus problems across implementations.
Lessons learned:
- Wycheproof catches subtle encoding bugs
- Reusable test harnesses pay dividends
- Test vector comments and flags help diagnose issues
- Even popular libraries benefit from systematic test vector validation
Advanced Usage
Tips and Tricks
Common Mistakes
Related Skills
Tool Skills
Technique Skills
Related Domain Skills
Skill Dependency Map
Resources
Official Repository
The official repository contains:
- All test vectors in
testvectors/andtestvectors_v1/ - JSON schemas in
schemas/ - Reference implementations in Java and JavaScript
- Documentation in
doc/
Real-World Examples
The pycryptodome library integrates Wycheproof test vectors in their test suite, demonstrating best practices for Python crypto implementations.
Community Resources
- C2SP Community - Cryptographic specifications and standards community maintaining Wycheproof
- Wycheproof issues tracker - Report bugs in test vectors or suggest new constructions
Summary
Wycheproof is an essential tool for validating cryptographic implementations against known attack vectors and edge cases. By integrating Wycheproof test vectors into your testing workflow:
- Catch subtle encoding and validation bugs
- Prevent signature malleability issues
- Ensure consistent behavior across implementations
- Benefit from community-contributed test vectors
- Protect against known cryptographic vulnerabilities
The investment in writing a reusable testing harness pays dividends through continuous validation as new test vectors are added to the Wycheproof repository.

