PT-2026-28568 · Pypi · Ecdsa

·

CVE-2026-33936

·

Published

2026-03-27

·

Updated

2026-07-13

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions ecdsa versions prior to 0.19.2
Description The ecdsa package, a Python implementation of ECC, contains a flaw in its DER parsing functions. Specifically, ecdsa.der.remove octet string() incorrectly accepts truncated DER data where the declared length exceeds the actual buffer size. This can lead to SigningKey.from der() raising an internal IndexError instead of a clean rejection of malformed DER, potentially causing a denial of service when parsing untrusted DER private keys. A crafted DER input can trigger this issue.
Recommendations Upgrade to ecdsa version 0.19.2 or later.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-CQ05396
CLEANSTART-2026-SO50412
CVE-2026-33936
ECHO-DC11-DAA6-FC93
GHSA-9F5J-8JWJ-X28G
OESA-2026-1836
OESA-2026-1837
OESA-2026-1838
OESA-2026-1839
OPENSUSE-SU-2026:10468-1
OPENSUSE-SU-2026:21078-1
PYSEC-2026-2467
SUSE-SU-2026:1436-1
SUSE-SU-2026:1608-1
SUSE-SU-2026:22158-1

Affected Products

Ecdsa