CVE-2026-26007Disclosure(cryptography.io / cryptography)

LOWCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch cryptography.io cryptography systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5.

2.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-345CWE-354

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cryptography

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 16 mentions across 10 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 14 signals
  • Disclosure: 9 classified signals
  • General: 1 classified signal
  • Peaked 7d ago at 4 mentions (2026-02-12); latest day: 1
  • 16 total mentions across 10 days

Affected systems

Products
cryptography

Deep dive

Activity timeline16 mentions / 10d
01234Mentions · 2026-02-10: 2Mentions · 2026-02-11: 1Mentions · 2026-02-12: 4Mentions · 2026-02-13: 2Mentions · 2026-02-14: 2Mentions · 2026-02-19: 1Mentions · 2026-03-17: 1Mentions · 2026-03-22: 1Mentions · 2026-05-21: 1Mentions · 2026-07-09: 1PoC Mentioned / Linked · 2026-05-21: 1Patch / Workaround · 2026-02-10: 1Patch / Workaround · 2026-02-11: 1Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-02-14: 2Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-07-09: 1Technical Details · 2026-02-10: 2Technical Details · 2026-02-11: 1Technical Details · 2026-02-12: 4Technical Details · 2026-02-13: 2Technical Details · 2026-02-19: 1Technical Details · 2026-03-17: 1Technical Details · 2026-03-22: 1Technical Details · 2026-05-21: 1Technical Details · 2026-07-09: 102-1002-1102-1202-1302-1402-1903-1703-2205-2107-09
Signal classification4 categories
Disclosure
956.3%
Patch
531.3%
General
16.3%
False Positive
16.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-102
Disclosure2
2026-02-111
Patch1
2026-02-124
Disclosure3General1
2026-02-132
Disclosure1False Positive1
2026-02-142
Patch2
2026-02-191
Patch1
2026-03-171
Disclosure1
2026-03-221
Disclosure1
2026-05-211
Disclosure1
2026-07-091
Patch1
Full discourse16 posts
  • Muhammad Kamel Qadah@Kamelkadah99
    Patch

    🔒 3. Comprehensive Security Update (Ongoing) Focus: Protection against CVE-2026-26007 Updating all security dependencies Strengthening protection against DoS #pinetwork #picoin https://t.co/THoh9KdUeg

    Post summary

    The post announces a security update that patches CVE-2026-26007 by updating all dependencies to strengthen DoS protection.

    38011713.6K
    6.7K followersView on X
  • Atum@Atuml1
    False Positive

    We found a CVSS 8.2 flaw CVE-2026-26007 in pyca/cryptography — the most widely used cryptolib in Python. https://securityonline.info/cve-2026-26007-python-cryptography-flaw-cvss-8-2-leaks-private-keys/ reported it as "full private key disclosure" Let's clarify: the vulnerability only leaks the least significant bits (e.g., 3 bits when cofactor = 8 ).

    Post summary

    The message reports CVE‑2026‑26007 in pyca/cryptography with a CVSS score of 8.2, notes prior claims of full key leakage, but clarifies that only the least significant bits are exposed, effectively debunking the severity claim.

    1512182.2K
    217 followersView on X
  • Open Source Security mailing list@oss_security
    Patch

    CVE-2026-26007 fixed in PyCA cryptography 46.0.5 https://www.openwall.com/lists/oss-security/2026/02/10/4 An attacker could create a malicious public key that reveals portions of your private key when using certain uncommon elliptic curves (binary curves)

    Post summary

    CVE-2026-26007, which allows malicious public keys on binary elliptic curves to leak parts of private keys, is fixed in PyCA cryptography 46.0.5.

    01052770
    4.4K followersView on X
  • Heroes Cyber Security@hcs_ctf
    Disclosure

    We recently published research on a cryptographic validation flaw in the widely used Python cryptography library (CVE-2026-26007). The package is extremely popular, with over 206 million downloads last week and 806 million downloads last month! https://hcs-team.com/blog/cve-2026-26007/ https://t.co/ZjSasnTciw

    Post summary

    Researchers announced the discovery of a cryptographic validation flaw (CVE-2026-26007) in the popular Python cryptography library, highlighting its widespread use.

    11040104
    54 followersView on X
  • Misbar | مسبار@MisbarSec
    Disclosure

    🚨 ثغرة في مكتبة Python تسمح بتسريب Private Keys اكتشفوا ثغرة خطيرة CVE-2026-26007 في مكتبة cryptography الخاصة بـ Python. هذه الثغرة ذات تصنيف CVSS 8.2 قد تسمح للمهاجمين بالوصول إلى المفاتيح الخاصة، مما يعرض البيانات الحساسة للخطر. التأثير كبير على التطبيقات التي تعتمد على هذه المكتبة لحماية اتصالاتها وبياناتها. 💡 الحماية: - حدث مكتبة cryptography لأحدث إصدار متوفر. - راجع سجلات الوصول والمراقبة بحثًا عن أي نشاط مشبوه. - قم بتطبيق مبدأ أقل الامتيازات صلاحيات على الوصول للمفاتيح الخاصة. 🔗 https://securityonline.info/cve-2026-26007-python-cryptography-flaw-cvss-8-2-leaks-private-keys/ #الأمن_السيبراني #Python #Vulnerability #CVE

    Post summary

    A new CVE-2026-26007 vulnerability in Python’s cryptography library can leak private keys; users should update to the latest version to mitigate the risk.

    0003056
    51 followersView on X
  • VaultKeepR - Decentralized Password Manager@vaultkeepr_xyz
    Disclosure

    Wrote about CVE-2026-26007. A missing subgroup validation check in pyca/cryptography let legacy curves leak private keys during ECDH. https://dev.to/vaultkeepr_xyz/cve-2026-26007-subgroup-confinement-attack-in-pycacryptography-7ne

    Post summary

    Highlights a subgroup validation flaw in pyca/cryptography that allows legacy curves to leak private keys during ECDH, with a link to a blog post for further details.

    0002092
    13 followersView on X
  • sunday peter π@sundaypeter8110
    Patch

    🔒 3. Comprehensive Security Update (Ongoing) Focus: Protection against CVE-2026-26007 Updating all security dependencies Strengthening protection against DoS #pinetwork #picoin https://t.co/hcpU7AfLvG

    Post summary

    A comprehensive security update is announced to protect against CVE‑2026‑26007 by updating all security dependencies and strengthening DoS defenses.

    00020217
    5.0K followersView on X
  • キタきつね@foxbook
    Disclosure

    CVE-2026-26007: Pythonの暗号化の脆弱性 (CVSS 8.2) により秘密鍵が漏洩する CVE-2026-26007: Python Cryptography Flaw (CVSS 8.2) Leaks Private Keys #DailyCyberSecurity (Feb 12) https://securityonline.info/cve-2026-26007-python-cryptography-flaw-cvss-8-2-leaks-private-keys/

    Post summary

    The post announces the discovery of CVE‑2026‑26007, a Python cryptography flaw that leaks private keys, with a CVSS score of 8.2, but provides no PoC, exploit code, patch information, or evidence of active exploitation.

    00010301
    4.7K followersView on X
  • まこ@tex2e
    General

    >RT Pythonのcryptographyパッケージは脆弱性(CVE-2026-26007)見てヒヤッとしたけど、今回の脆弱性の影響はSECTの楕円曲線だけで、普段使うのはSECPだから思ったより影響なさそうで安心した

    Post summary

    The tweet notes the CVE-2026-26007 vulnerability in Python's cryptography package, indicating it only impacts SECT elliptic curves and not the commonly used SECP curves, without mentioning any PoC, exploit, or patch.

    00010290
    1.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26007 cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurve… https://www.cve.org/CVERecord?id=CVE-2026-26007

    Post summary

    A brief disclosure of CVE-2026-26007 in the Python cryptography package, noting that versions prior to 46.0.5 are vulnerable and implying a patch via that release.

    00010243
    56.5K followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Patch

    New critical CVEs in 'cryptography' (CVE-2024-12797, CVE-2026-26007, CVE-2026-34073, July 8) expose TLS/DNS to MITM & forgery. Immediate patching vital for data privacy & integrity in transit. #Cybersecurity #News

    Post summary

    The post announces three critical CVEs in the cryptography library that enable TLS/DNS man‑in‑the‑middle attacks and forgery, urging immediate patching to protect data privacy and integrity.

    0000087
    14 followersView on X
  • Komodo Cyber Security@Komodosec
    Disclosure

    #VulnerabilityReport #CVE202626007 CVE-2026-26007: Python Cryptography Flaw (CVSS 8.2) Leaks Private Keys https://securityonline.info/cve-2026-26007-python-cryptography-flaw-cvss-8-2-leaks-private-keys/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet announces CVE-2026-26007, a Python cryptography flaw with CVSS 8.2 that leaks private keys, but provides no details on PoCs, exploits, or patches.

    0000058
    1.5K followersView on X
  • Kairo@kairo_security
    Patch

    @polkapheen ECC isn't expiring—it's just bleeding from small-subgroup attacks like CVE-2026-26007 in pyca/cryptography. Always validate points belong to the prime-order subgroup, or watch your keys leak.

    Post summary

    The tweet highlights CVE-2026-26007, a small‑subgroup attack in pyca/cryptography, and advises validating ECC points to mitigate key leakage.

    0000025
    151 followersView on X
  • CrowdCyber 🌐@CrowdCyber_Com
    Disclosure

    CVE-2026-26007: Python Cryptography Flaw (CVSS 8.2) Leaks Private Keys https://securityonline.info/cve-2026-26007-python-cryptography-flaw-cvss-8-2-leaks-private-keys/

    Post summary

    The text announces CVE-2026-26007 as a Python cryptography flaw with CVSS 8.2 that can leak private keys, but provides no evidence of exploitation, PoC, or patch.

    00000106
    298 followersView on X
  • Karma-X@Karma_X_Inc
    Disclosure

    CVE-2026-26007: Python Cryptography Flaw (CVSS 8.2) Leaks Private Keys https://securityonline.info/cve-2026-26007-python-cryptography-flaw-cvss-8-2-leaks-private-keys/

    Post summary

    The text announces CVE-2026-26007, a Python cryptography flaw with CVSS 8.2 that leaks private keys, without providing a PoC, exploit code, or active exploitation details.

    0000076
    73 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-26007: Living on the Edge: Subgroup Attacks in Python Cryptography A high-severity flaw in the standard Python `cryptography` library allows attackers to recover private keys when using binary elliptic curves. By exploiting missing subgroup v... https://cvereports.com/reports/CVE-2026-26007

    Post summary

    The report discloses a high‑severity flaw in Python’s cryptography library that allows private‑key recovery due to missing subgroup checks when using binary elliptic curves.

    0000069
    27 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcryptography.iocryptography-python-

Explore more