<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T21:52:52.789476+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2020-01480</id>
    <title>bdu:2020-01480</title>
    <updated>2026-10-03T21:52:52.861032+00:00</updated>
    <content>bdu:2020-01480</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2020-01480"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-duplicity-cve-2019-14853</id>
    <title>BREW-duplicity-CVE-2019-14853 — ecdsa Denial of Service vulnerability in signature verification and signature malleability</title>
    <updated>2026-10-03T21:52:52.861066+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: duplicity</p>
<p>## possible DoS in signature verification and signature malleability</p>
<p>### Impact
Code using `VerifyingKey.verify()` and `VerifyingKey.verify_digest()` may receive exceptions other than the documented `BadSignatureError` when signatures are malformed. If those other exceptions are not caught, they may lead to program termination and thus Denial of Service</p>
<p>Code using `VerifyingKey.verify()` and `VerifyingKey.verify_digest()` with `sigdecode` option using `ecdsa.util.sigdecode_der` will accept signatures even if they are not properly formatted DER. This makes the signatures malleable. It impacts only applications that later sign the signatures or verify signatures of signatures, e.g. Bitcoin.</p>
<p>All versions between 0.5 and 0.13.2 (inclusive) are thought to be vulnerable. Code before 0.5 may be vulnerable but didn't receive extended analysis to rule this issue out.</p>
<p>### Patches
The patches have been merged to `master` branch in https://github.com/warner/python-ecdsa/pull/115.
The backported patches for a release in the 0.13 branch are in https://github.com/warner/python-ecdsa/pull/124</p>
<p>They are part of the 0.13.3 release.</p>
<p>There are no plans to backport them to earlier releases.</p>
<p>### Workarounds
It may be possible to prevent the Denial of Service by catching also `UnexpectedDER`, `IndexError` and `AssertionError` exceptions. That list hasn't been verified to be complete though. If those exceptions are raised, the signature verification process should consider the signature to b…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-duplicity-cve-2019-14853"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-56702</id>
    <title>EUVD-2026-56702</title>
    <updated>2026-10-03T21:52:52.861121+00:00</updated>
    <content>EUVD-2026-56702</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-56702"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-14853</id>
    <title>fkie_cve-2019-14853</title>
    <updated>2026-10-03T21:52:52.861136+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatures could raise unexpected exceptions (or no exceptions at all), which could lead to a denial of service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-14853"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pwfw-mgfj-7g3g</id>
    <title>GHSA-pwfw-mgfj-7g3g — ecdsa Denial of Service vulnerability in signature verification and signature malleability</title>
    <updated>2026-10-03T21:52:52.861157+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: ecdsa</p>
<p>## possible DoS in signature verification and signature malleability</p>
<p>### Impact
Code using `VerifyingKey.verify()` and `VerifyingKey.verify_digest()` may receive exceptions other than the documented `BadSignatureError` when signatures are malformed. If those other exceptions are not caught, they may lead to program termination and thus Denial of Service</p>
<p>Code using `VerifyingKey.verify()` and `VerifyingKey.verify_digest()` with `sigdecode` option using `ecdsa.util.sigdecode_der` will accept signatures even if they are not properly formatted DER. This makes the signatures malleable. It impacts only applications that later sign the signatures or verify signatures of signatures, e.g. Bitcoin.</p>
<p>All versions between 0.5 and 0.13.2 (inclusive) are thought to be vulnerable. Code before 0.5 may be vulnerable but didn't receive extended analysis to rule this issue out.</p>
<p>### Patches
The patches have been merged to `master` branch in https://github.com/warner/python-ecdsa/pull/115.
The backported patches for a release in the 0.13 branch are in https://github.com/warner/python-ecdsa/pull/124</p>
<p>They are part of the 0.13.3 release.</p>
<p>There are no plans to backport them to earlier releases.</p>
<p>### Workarounds
It may be possible to prevent the Denial of Service by catching also `UnexpectedDER`, `IndexError` and `AssertionError` exceptions. That list hasn't been verified to be complete though. If those exceptions are raised, the signature verification process should consider the signature to b…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pwfw-mgfj-7g3g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-14853</id>
    <title>gsd-2019-14853</title>
    <updated>2026-10-03T21:52:52.861198+00:00</updated>
    <content>gsd-2019-14853</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-14853"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2019:2472-1</id>
    <title>openSUSE-SU-2019:2472-1 — Security update for python-ecdsa</title>
    <updated>2026-10-03T21:52:52.861211+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-ecdsa</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2019:2472-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2019-177</id>
    <title>PYSEC-2019-177</title>
    <updated>2026-10-03T21:52:52.861228+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: ecdsa</p>
<p>An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatures could raise unexpected exceptions (or no exceptions at all), which could lead to a denial of service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2019-177"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:4702</id>
    <title>RHSA-2021:4702 — Red Hat Security Advisory: Satellite 6.10 Release</title>
    <updated>2026-10-03T21:52:52.861246+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python-ecdsa: Unexpected and  undocumented exceptions during signature decoding python-ecdsa: DER encoding is not being verified in signatures rubygem-activerecord-session_store: hijack sessions by using timing attacks targeting the session id rake: OS Command Injection via egrep in Rake::FileList guava: local information disclosure via temporary directory created with unsafe permissions PyYAML: incomplete fix for CVE-2020-1747 rubygem-nokogiri: XML external entity injection via Nokogiri::XML::Schema Satellite: Azure compute resource secret_key leak to authenticated users foreman: possible man-in-the-middle in smart_proxy realm_freeipa Satellite: BMC controller credential leak via API python-aiohttp: Open redirect in aiohttp.web_middlewares.normalize_path_middleware rubygem-actionpack: Possible Information Disclosure / Unintended Method Execution in Action Pack rails: Possible Denial of Service vulnerability in Action Dispatch rails: Possible DoS Vulnerability in Action Controller Token Authentication django: potential directory-traversal via uploaded files rubygem-puma: incomplete fix for CVE-2019-16770 allows Denial of Service (DoS) django: Potential directory-traversal via uploaded files rubygem-addressable: ReDoS in templates django: Potential directory traversal via ``admindocs`` python-urllib3: ReDoS in the parsing of authority part of URL django: Possible indeterminate SSRF, RFI, and LFI attacks since validators accepted leading zeros in IPv4 addresses</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:4702"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2019:2891-1</id>
    <title>SUSE-SU-2019:2891-1 — Security update for python-ecdsa</title>
    <updated>2026-10-03T21:52:52.861292+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-ecdsa</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2019:2891-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-14853</id>
    <title>UBUNTU-CVE-2019-14853</title>
    <updated>2026-10-03T21:52:52.861307+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: python-ecdsa, Ubuntu:18.04:LTS: python-ecdsa</p>
<p>An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatures could raise unexpected exceptions (or no exceptions at all), which could lead to a denial of service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-14853"/>
  </entry>
</feed>
