← Vulnerability feed

Vulnerability record · CVE-2026-26007 · published 10 February 2026

CVE-2026-26007: Cryptography.io cryptography insufficient verification of data authenticity vulnerability

CCryptography.Io · Cryptography

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5.

8.2 CVSS 4.0 High EPSS 0.34% · top 75.2% CWE-345 · Insufficient verification of data authenticityCWE-354 · CWE-354
8.2CVSS 4.0 base score
0.34%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
26References
10 Sep 2026Last modified by NVD

Description

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5.

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-26007 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2020-36242Cryptography.io cryptography integer overflow vulnerabilityIn the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an in…EPSS 6.7%7.5CVE-2024-26130Cryptography.io cryptography null pointer dereference vulnerabilitycryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to versi…EPSS 0.83%7.5CVE-2023-50782Redhat ansible automation platform observable discrepancy vulnerabilityA flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA …EPSS 1.1%7.5CVE-2023-49083Cryptography.io cryptography null pointer dereference vulnerabilitycryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_certificates` or `loa…EPSS 0.99%7.5CVE-2023-38325Cryptography.io cryptography improper certificate validation vulnerabilityThe cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.EPSS 0.73%7.5CVE-2016-9243Cryptography.io cryptography vulnerabilityHKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.EPSS 3.5%6.9CVE-2026-39892Cryptography.io cryptography memory buffer overflow vulnerabilitycryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contig…EPSS 0.76%6.5CVE-2023-23931Cryptography.io cryptography vulnerabilitycryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` wou…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2026-26007), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.