Skip to main content
EPSS 0.3%top 72%

python-cryptography vulnerability (CVE-2026-26007)

0
Medium
Published: 03/12/2026 (03/12/2026, 14:16:11 UTC)
Source: GCVE Database
Product: python-cryptography

Description

It was discovered that python-cryptography incorrectly handled subgroup validation for SECT curves. A remote attacker could use this issue to perform a subgroup attack and possibly recover the least significant bits of private keys.

CVSS v3.1

Score 7.4high

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected software

Affected versions
Red HatRed Hat Enterprise LinuxRed Hat Enterprise Linux AppStream (v. 9)srcfence-agents-0:4.10.0-98.el9_7.12.src< 46.0.5Red Hat Enterprise Linux AppStream (v. 8)Red Hat Enterprise Linux HighAvailability (v. 8)Red Hat Enterprise Linux ResilientStorage (v. 8)Red Hat Hardened Imagespython-cryptography-main@src<3.4.8-1ubuntu2.3<41.0.7-4ubuntu0.3<43.0.0-1ubuntu1.1

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 19:50:31 UTC

Technical Analysis

The vulnerability (CVE-2026-26007) in the python cryptography package arises from missing subgroup validation for SECT elliptic curves. An attacker can supply a public key point from a small-order subgroup, which leads to leakage of private key bits during ECDH shared secret computation or enables forging signatures in ECDSA on the small subgroup. This compromises the integrity of cryptographic operations relying on these curves. The flaw is challenging to exploit but affects cryptography library users, including Red Hat Enterprise Linux 8 and related products. Red Hat has analyzed the issue and currently does not provide a mitigation or fix that meets their criteria for ease of use, applicability, or stability.

Potential Impact

The vulnerability can lead to loss of integrity in encrypted communication channels by allowing attackers to forge signatures or leak private key information in cryptographic operations using SECT curves. This affects applications relying on the python cryptography package for ECDSA signature verification and ECDH key negotiation. The flaw does not impact availability or confidentiality directly but compromises data integrity and non-repudiation.

Mitigation Recommendations

Red Hat currently does not offer a mitigation or fix that meets their criteria for deployment ease, applicability, or stability. Users should monitor Red Hat advisories for updates. No immediate action is available to fully mitigate this vulnerability at this time.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:12176
Cve Count
3
Additional Cves
["CVE-2026-30922","CVE-2026-32597"]
State
PUBLISHED

Threat ID: 6a160980e29bf47b5064cfbe

Added to database: 05/26/2026, 20:58:40 UTC

Last enriched: 08/12/2026, 19:50:31 UTC

Last updated: 09/13/2026, 22:01:32 UTC

Views: 95

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses