OESA-2026-1839

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-1839
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-1839.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-1839
Upstream
Published
2026-04-11T14:03:22Z
Modified
2026-04-11T14:17:39.572808Z
Summary
python-ecdsa security update
Details

This is an easy-to-use implementation of ECDSA cryptography (Elliptic Curve Digital Signature Algorithm), implemented purely in Python, released under the MIT license. With this library, you can quickly create keypairs (signing key and verifying key), sign messages, and verify the signatures. The keys and signatures are very short, making them easy to handle and incorporate into other protocols.

Security Fix(es):

The ecdsa PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve Diffie-Hellman). Prior to version 0.19.2, an issue in the low-level DER parsing functions can cause unexpected exceptions to be raised from the public API functions. ecdsa.der.remove_octet_string() accepts truncated DER where the encoded length exceeds the available buffer. For example, an OCTET STRING that declares a length of 4096 bytes but provides only 3 bytes is parsed successfully instead of being rejected. Because of that, a crafted DER input can cause SigningKey.from_der() to raise an internal exception (IndexError: index out of bounds on dimension 1) rather than cleanly rejecting malformed DER (e.g., raising UnexpectedDER or ValueError). Applications that parse untrusted DER private keys may crash if they do not handle unexpected exceptions, resulting in a denial of service. Version 0.19.2 patches the issue.(CVE-2026-33936)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:24.03-LTS-SP1 / python-ecdsa

Package

Name
python-ecdsa
Purl
pkg:rpm/openEuler/python-ecdsa&distro=openEuler-24.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.18.0-3.oe2403sp1

Ecosystem specific

{
    "noarch": [
        "python-ecdsa-help-0.18.0-3.oe2403sp1.noarch.rpm",
        "python3-ecdsa-0.18.0-3.oe2403sp1.noarch.rpm"
    ],
    "src": [
        "python-ecdsa-0.18.0-3.oe2403sp1.src.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-1839.json"