CVE-2026-26007: Python Cryptography Flaw (CVSS 8.2) Leaks Private Keys
ID: 1ad5ae53-7506-5eef-b8f4-917fdadfab4c
STIX ID: report--1ad5ae53-7506-5eef-b8f4-917fdadfab4c
Feed Name: securityonline.info
Threat Score
A high-severity vulnerability (CVE-2026-26007, CVSS 8.2) in the Python cryptography package fails to validate that SECT-curve public key points belong to the prime-order subgroup, enabling subgroup attacks that can leak private key bits during ECDH and allow ECDSA forgeries; maintainers released a fix in version 46.0.5 and developers should upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
