CVE-2026-33936
Description
The ecdsa PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve Diffie-Hellman). Prior to version 0.19.2, an issue in the low-level DER parsing functions can cause unexpected exceptions to be raised from the public API functions. ecdsa.der.remove_octet_string() accepts truncated DER where the encoded length exceeds the available buffer. For example, an OCTET STRING that declares a length of 4096 bytes but provides only 3 bytes is parsed successfully instead of being rejected. Because of that, a crafted DER input can cause SigningKey.from_der() to raise an internal exception (IndexError: index out of bounds on dimension 1) rather than cleanly rejecting malformed DER (e.g., raising UnexpectedDER or ValueError). Applications that parse untrusted DER private keys may crash if they do not handle unexpected exceptions, resulting in a denial of service. Version 0.19.2 patches the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ecdsaPyPI | < 0.19.2 | 0.19.2 |
Affected products
10- osv-coords9 versionspkg:apk/chainguard/airflow-2pkg:apk/chainguard/awxpkg:pypi/ecdsapkg:rpm/opensuse/python-ecdsa&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/python-ecdsa&distro=openSUSE%20Tumbleweedpkg:rpm/suse/python-ecdsa&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7pkg:rpm/suse/python-ecdsa&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%203%2015%20SP7pkg:rpm/suse/python-ecdsa&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/python-ecdsa&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0
< 2.11.2-r5+ 8 more
- (no CPE)range: < 2.11.2-r5
- (no CPE)range: < 24.6.1-r33
- (no CPE)range: < 0.19.2
- (no CPE)range: < 0.18.0-150400.12.6.1
- (no CPE)range: < 0.19.2-1.1
- (no CPE)range: < 0.13.3-150000.3.10.1
- (no CPE)range: < 0.18.0-150400.12.6.1
- (no CPE)range: < 0.19.1-160000.4.1
- (no CPE)range: < 0.19.1-160000.4.1
Patches
Vulnerability mechanics
References
5- github.com/tlsfuzzer/python-ecdsa/commit/bd66899550d7185939bf27b75713a2ac9325a9d3nvdPatchWEB
- github.com/tlsfuzzer/python-ecdsa/security/advisories/GHSA-9f5j-8jwj-x28gnvdExploitMitigationVendor AdvisoryWEB
- github.com/advisories/GHSA-9f5j-8jwj-x28gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-33936ghsaADVISORY
- github.com/tlsfuzzer/python-ecdsa/releases/tag/python-ecdsa-0.19.2nvdProductRelease NotesWEB
News mentions
0No linked articles in our index yet.