PT-2026-7473 · Sect+5 · Sect+5

·

CVE-2026-26007

·

Published

2026-02-10

·

Updated

2026-08-25

CVSS v4.0

8.2

High

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions cryptography versions prior to 46.0.5
Description A validation flaw exists where the functions public key from numbers() (or EllipticCurvePublicNumbers.public key()), EllipticCurvePublicNumbers.public key(), load der public key(), and load pem public key() fail to verify if a point belongs to the expected prime-order subgroup of the curve. This allows an attacker to provide a public key point P from a small-order subgroup, which specifically impacts SECT curves. This can lead to security issues during signature verification (ECDSA) and shared key negotiation (ECDH). In ECDH, when a victim computes the shared secret as S = [victim private key]P, information about victim private key mod (small subgroup order) is leaked. For curves with a cofactor greater than 1, this reveals the least significant bits of the private key. Additionally, using these weak public keys in ECDSA makes it possible to forge signatures on the small subgroup.
Recommendations Update cryptography to version 46.0.5.

Exploit

Fix

DoS

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:12176
AZL-77447
AZL-77454
BDU:2026-11378
CLEANSTART-2026-AN24336
CLEANSTART-2026-AZ09261
CLEANSTART-2026-CQ05396
CLEANSTART-2026-EM82280
CLEANSTART-2026-FU07345
CLEANSTART-2026-HP19968
CLEANSTART-2026-IR98353
CLEANSTART-2026-KE11953
CLEANSTART-2026-MR94452
CLEANSTART-2026-NL78203
CLEANSTART-2026-NM83456
CLEANSTART-2026-QE89118
CLEANSTART-2026-SO50412
CLEANSTART-2026-WQ85001
CLEANSTART-2026-WU03167
CVE-2026-26007
ECHO-9290-B93D-4581
GHSA-R6PH-V2QM-Q3C2
OESA-2026-1669
OESA-2026-1670
OESA-2026-1671
OESA-2026-1672
OPENSUSE-SU-2026:10205-1
OPENSUSE-SU-2026:10539-1
OPENSUSE-SU-2026:20506-1
PYSEC-2026-2141
RHSA-2026:12176
RHSA-2026:13512
RHSA-2026:13672
RHSA-2026:19355
RHSA-2026:21431
RHSA-2026:21517
RHSA-2026:22330
RHSA-2026:7295
SUSE-SU-2026:20655-1
SUSE-SU-2026:20706-1
SUSE-SU-2026:21021-1
SUSE-SU-2026:21165-1
USN-8087-1
USN-8087-3

Affected Products

Linuxmint
Red Os
Rocky Linux
Sect
Ubuntu
Cryptography