PT-2026-28568 · Pypi · Ecdsa

0Xmrma

·

Published

2026-03-27

·

Updated

2026-05-13

·

CVE-2026-33936

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions ecdsa versions prior to 0.19.2
Description The ecdsa package, a Python implementation of ECC, contains a flaw in its DER parsing functions. Specifically, ecdsa.der.remove octet string() incorrectly accepts truncated DER data where the declared length exceeds the actual buffer size. This can lead to SigningKey.from der() raising an internal IndexError instead of a clean rejection of malformed DER, potentially causing a denial of service when parsing untrusted DER private keys. A crafted DER input can trigger this issue.
Recommendations Upgrade to ecdsa version 0.19.2 or later.

Exploit

Fix

DoS

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-33936
ECHO-DC11-DAA6-FC93
GHSA-9F5J-8JWJ-X28G
OESA-2026-1836
OESA-2026-1837
OESA-2026-1838
OESA-2026-1839
OPENSUSE-SU-2026:10468-1
SUSE-SU-2026:1436-1
SUSE-SU-2026:1608-1

Affected Products

Ecdsa