<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T01:51:21.507195+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-duplicity-cve-2026-33936</id>
    <title>BREW-duplicity-CVE-2026-33936 — python-ecdsa: Denial of Service via improper DER length validation in crafted private keys</title>
    <updated>2026-10-03T01:51:21.894660+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: duplicity</p>
<p>## Summary</p>
<p>An issue in the low-level DER parsing functions can cause unexpected exceptions to be raised from the public API functions.</p>
<p>1. `ecdsa.der.remove_octet_string()` accepts truncated DER where the encoded length exceeds the available buffer. For example, an OCTET STRING that declares a length of 4096 bytes but provides only 3 bytes is parsed successfully instead of being rejected.</p>
<p>2. Because of that, a crafted DER input can cause `SigningKey.from_der()` to raise an internal exception (`IndexError: index out of bounds on dimension 1`) rather than cleanly rejecting malformed DER (e.g., raising `UnexpectedDER` or `ValueError`). Applications that parse untrusted DER private keys may crash if they do not handle unexpected exceptions, resulting in a denial of service.</p>
<p>## Impact</p>
<p>Potential denial-of-service when parsing untrusted DER private keys due to unexpected internal exceptions, and malformed DER acceptance due to missing bounds checks in DER helper functions.</p>
<p>## Reproduction</p>
<p>Attach and run the following PoCs:</p>
<p>###  poc_truncated_der_octet.py</p>
<p>```python
from ecdsa.der import remove_octet_string, UnexpectedDER</p>
<p># OCTET STRING (0x04)
# Declared length: 0x82 0x10 0x00  -&gt; 4096 bytes
# Actual body: only 3 bytes -&gt; truncated DER
bad = b"\x04\x82\x10\x00" + b"ABC"</p>
<p>try:
    body, rest = remove_octet_string(bad)
    print("[BUG] remove_octet_string accepted truncated DER.")
    print("Declared length=4096, actual body_len=", len(body), "rest_len=", len(rest))
    print(…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-duplicity-cve-2026-33936"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0406</id>
    <title>certfr-2026-avi-0406 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
    <updated>2026-10-03T01:51:21.894795+00:00</updated>
    <content>certfr-2026-avi-0406</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0406"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-cq05396</id>
    <title>Withdrawn: CLEANSTART-2026-CQ05396 — Security fixes for CVE-2025-32962, CVE-2025-58065, CVE-2026-22815, CVE-2026-25645, CVE-2026-26007, CVE-2026-27205, CVE-…</title>
    <updated>2026-10-03T01:51:21.894826+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: airflow-2</p>
<p>Multiple security vulnerabilities affect the airflow-2 package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-cq05396"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-278434</id>
    <title>EUVD-2026-278434</title>
    <updated>2026-10-03T01:51:21.894865+00:00</updated>
    <content>EUVD-2026-278434</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-278434"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33936</id>
    <title>fkie_cve-2026-33936</title>
    <updated>2026-10-03T01:51:21.894884+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve Diffie-Hellman). Prior to version 0.19.2, an issue in the low-level DER parsing functions can cause unexpected exceptions to be raised from the public API functions. `ecdsa.der.remove_octet_string()` accepts truncated DER where the encoded length exceeds the available buffer. For example, an OCTET STRING that declares a length of 4096 bytes but provides only 3 bytes is parsed successfully instead of being rejected. Because of that, a crafted DER input can cause `SigningKey.from_der()` to raise an internal exception (`IndexError: index out of bounds on dimension 1`) rather than cleanly rejecting malformed DER (e.g., raising `UnexpectedDER` or `ValueError`). Applications that parse untrusted DER private keys may crash if they do not handle unexpected exceptions, resulting in a denial of service. Version 0.19.2 patches the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-33936"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9f5j-8jwj-x28g</id>
    <title>GHSA-9f5j-8jwj-x28g — python-ecdsa: Denial of Service via improper DER length validation in crafted private keys</title>
    <updated>2026-10-03T01:51:21.894925+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: ecdsa</p>
<p>## Summary</p>
<p>An issue in the low-level DER parsing functions can cause unexpected exceptions to be raised from the public API functions.</p>
<p>1. `ecdsa.der.remove_octet_string()` accepts truncated DER where the encoded length exceeds the available buffer. For example, an OCTET STRING that declares a length of 4096 bytes but provides only 3 bytes is parsed successfully instead of being rejected.</p>
<p>2. Because of that, a crafted DER input can cause `SigningKey.from_der()` to raise an internal exception (`IndexError: index out of bounds on dimension 1`) rather than cleanly rejecting malformed DER (e.g., raising `UnexpectedDER` or `ValueError`). Applications that parse untrusted DER private keys may crash if they do not handle unexpected exceptions, resulting in a denial of service.</p>
<p>## Impact</p>
<p>Potential denial-of-service when parsing untrusted DER private keys due to unexpected internal exceptions, and malformed DER acceptance due to missing bounds checks in DER helper functions.</p>
<p>## Reproduction</p>
<p>Attach and run the following PoCs:</p>
<p>###  poc_truncated_der_octet.py</p>
<p>```python
from ecdsa.der import remove_octet_string, UnexpectedDER</p>
<p># OCTET STRING (0x04)
# Declared length: 0x82 0x10 0x00  -&gt; 4096 bytes
# Actual body: only 3 bytes -&gt; truncated DER
bad = b"\x04\x82\x10\x00" + b"ABC"</p>
<p>try:
    body, rest = remove_octet_string(bad)
    print("[BUG] remove_octet_string accepted truncated DER.")
    print("Declared length=4096, actual body_len=", len(body), "rest_len=", len(rest))
    print(…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9f5j-8jwj-x28g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-33936</id>
    <title>msrc_CVE-2026-33936 — python-ecdsa: Denial of Service via improper DER length validation in crafted private keys</title>
    <updated>2026-10-03T01:51:21.895009+00:00</updated>
    <content>msrc_CVE-2026-33936</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-33936"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1828</id>
    <title>OESA-2026-1828 — python-ecdsa security update</title>
    <updated>2026-10-03T01:51:21.895036+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: python-ecdsa</p>
<p>This is an easy-to-use implementation of ECDSA cryptography (Elliptic Curve Digital Signature Algorithm), implemented purely in Python, released under  the MIT license. With this library, you can quickly create keypairs (signing  key and verifying key), sign messages, and verify the signatures. The keys  and signatures are very short, making them easy to handle and incorporate  into other protocols.

Security Fix(es):</p>
<p>The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve Diffie-Hellman). Prior to version 0.19.2, an issue in the low-level DER parsing functions can cause unexpected exceptions to be raised from the public API functions. `ecdsa.der.remove_octet_string()` accepts truncated DER where the encoded length exceeds the available buffer. For example, an OCTET STRING that declares a length of 4096 bytes but provides only 3 bytes is parsed successfully instead of being rejected. Because of that, a crafted DER input can cause `SigningKey.from_der()` to raise an internal exception (`IndexError: index out of bounds on dimension 1`) rather than cleanly rejecting malformed DER (e.g., raising `UnexpectedDER` or `ValueError`). Applications that parse untrusted DER private keys may crash if they do not handle unexpected exceptions, resulting in a denial of service. Version 0.19.2 patches the issu…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1828"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10468-1</id>
    <title>openSUSE-SU-2026:10468-1 — python311-ecdsa-0.19.2-1.1 on GA media</title>
    <updated>2026-10-03T01:51:21.895088+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python311-ecdsa-0.19.2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10468-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2467</id>
    <title>PYSEC-2026-2467 — python-ecdsa: Denial of Service via improper DER length validation in crafted private keys</title>
    <updated>2026-10-03T01:51:21.895114+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: ecdsa</p>
<p>## Summary</p>
<p>An issue in the low-level DER parsing functions can cause unexpected exceptions to be raised from the public API functions.</p>
<p>1. `ecdsa.der.remove_octet_string()` accepts truncated DER where the encoded length exceeds the available buffer. For example, an OCTET STRING that declares a length of 4096 bytes but provides only 3 bytes is parsed successfully instead of being rejected.</p>
<p>2. Because of that, a crafted DER input can cause `SigningKey.from_der()` to raise an internal exception (`IndexError: index out of bounds on dimension 1`) rather than cleanly rejecting malformed DER (e.g., raising `UnexpectedDER` or `ValueError`). Applications that parse untrusted DER private keys may crash if they do not handle unexpected exceptions, resulting in a denial of service.</p>
<p>## Impact</p>
<p>Potential denial-of-service when parsing untrusted DER private keys due to unexpected internal exceptions, and malformed DER acceptance due to missing bounds checks in DER helper functions.</p>
<p>## Reproduction</p>
<p>Attach and run the following PoCs:</p>
<p>###  poc_truncated_der_octet.py</p>
<p>```python
from ecdsa.der import remove_octet_string, UnexpectedDER</p>
<p># OCTET STRING (0x04)
# Declared length: 0x82 0x10 0x00  -&gt; 4096 bytes
# Actual body: only 3 bytes -&gt; truncated DER
bad = b"\x04\x82\x10\x00" + b"ABC"</p>
<p>try:
    body, rest = remove_octet_string(bad)
    print("[BUG] remove_octet_string accepted truncated DER.")
    print("Declared length=4096, actual body_len=", len(body), "rest_len=", len(rest))
    print(…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2467"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22158-1</id>
    <title>SUSE-SU-2026:22158-1 — Security update for python-ecdsa</title>
    <updated>2026-10-03T01:51:21.895197+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-ecdsa</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22158-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33936</id>
    <title>UBUNTU-CVE-2026-33936</title>
    <updated>2026-10-03T01:51:21.895242+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: python-ecdsa, Ubuntu:18.04:LTS: python-ecdsa, Ubuntu:20.04:LTS: python-ecdsa, Ubuntu:22.04:LTS: python-ecdsa, Ubuntu:24.04:LTS: python-ecdsa, Ubuntu:25.10: python-ecdsa, Ubuntu:26.04:LTS: python-ecdsa</p>
<p>The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve Diffie-Hellman). Prior to version 0.19.2, an issue in the low-level DER parsing functions can cause unexpected exceptions to be raised from the public API functions. `ecdsa.der.remove_octet_string()` accepts truncated DER where the encoded length exceeds the available buffer. For example, an OCTET STRING that declares a length of 4096 bytes but provides only 3 bytes is parsed successfully instead of being rejected. Because of that, a crafted DER input can cause `SigningKey.from_der()` to raise an internal exception (`IndexError: index out of bounds on dimension 1`) rather than cleanly rejecting malformed DER (e.g., raising `UnexpectedDER` or `ValueError`). Applications that parse untrusted DER private keys may crash if they do not handle unexpected exceptions, resulting in a denial of service. Version 0.19.2 patches the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33936"/>
  </entry>
</feed>
