logo

CVE-2026-26007: Python Cryptography Flaw (CVSS 8.2) Leaks Private Keys

ID: 1ad5ae53-7506-5eef-b8f4-917fdadfab4c

STIX ID: report--1ad5ae53-7506-5eef-b8f4-917fdadfab4c

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-02-12

Date Updated: 2026-04-23

Author: Ddos

...
...

A high-severity vulnerability (CVE-2026-26007, CVSS 8.2) in the Python cryptography package fails to validate that SECT-curve public key points belong to the prime-order subgroup, enabling subgroup attacks that can leak private key bits during ECDH and allow ECDSA forgeries; maintainers released a fix in version 46.0.5 and developers should upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.