CVE-2026-26007

Vulnerability

CVE-2026-26007

cryptography: cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves

ecosystem: redhat:8, redhat:9

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5.

References
severityI
Important

type: vendor

source: secalert@redhat.com

CVSS3.1
7.4HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

AVNetwork
ACHigh
PRNone
UINone
SNot Changed
CHigh
IHigh
ANone

source: secalert@redhat.com

 CWE
CWE-354

Improper Validation of Integrity Check Value

source: secalert@redhat.com

published: 2026-02-10 21:42:56

modified: 2026-02-12 22:34:40

Detection

redhat:8
CVE-2026-26007

redhat-vex

OR

unfixedAffected

 

fence-agents-aliyun

package type: binary

type: version
unfixedAffected

 

fence-agents-all

package type: binary

type: version
unfixedAffected

 

fence-agents-amt-ws

package type: binary

type: version
unfixedAffected

 

fence-agents-apc

package type: binary

type: version
unfixedAffected

 

fence-agents-apc-snmp

package type: binary

type: version
unfixedAffected

 

fence-agents-aws

package type: binary

type: version
unfixedAffected

 

fence-agents-azure-arm

package type: binary

type: version
unfixedAffected

 

fence-agents-bladecenter

package type: binary

type: version
unfixedAffected

 

fence-agents-brocade

package type: binary

type: version
unfixedAffected

 

fence-agents-cisco-mds

package type: binary

type: version
unfixedAffected

 

fence-agents-cisco-ucs

package type: binary

type: version
unfixedAffected

 

fence-agents-common

package type: binary

type: version
unfixedAffected

 

fence-agents-compute

package type: binary

type: version
unfixedAffected

 

fence-agents-drac5

package type: binary

type: version
unfixedAffected

 

fence-agents-eaton-snmp

package type: binary

type: version
unfixedAffected

 

fence-agents-emerson

package type: binary

type: version
unfixedAffected

 

fence-agents-eps

package type: binary

type: version
unfixedAffected

 

fence-agents-gce

package type: binary

type: version
unfixedAffected

 

fence-agents-heuristics-ping

package type: binary

type: version
unfixedAffected

 

fence-agents-hpblade

package type: binary

type: version
unfixedAffected

 

fence-agents-ibm-powervs

package type: binary

type: version
unfixedAffected

 

fence-agents-ibm-vpc

package type: binary

type: version
unfixedAffected

 

fence-agents-ibmblade

package type: binary

type: version
unfixedAffected

 

fence-agents-ifmib

package type: binary

type: version
unfixedAffected

 

fence-agents-ilo-moonshot

package type: binary

type: version
unfixedAffected

 

fence-agents-ilo-mp

package type: binary

type: version
unfixedAffected

 

fence-agents-ilo-ssh

package type: binary

type: version
unfixedAffected

 

fence-agents-ilo2

package type: binary

type: version
unfixedAffected

 

fence-agents-intelmodular

package type: binary

type: version
unfixedAffected

 

fence-agents-ipdu

package type: binary

type: version
unfixedAffected

 

fence-agents-ipmilan

package type: binary

type: version
unfixedAffected

 

fence-agents-kdump

package type: binary

type: version
unfixedAffected

 

fence-agents-kubevirt

package type: binary

type: version
unfixedAffected

 

fence-agents-lpar

package type: binary

type: version
unfixedAffected

 

fence-agents-mpath

package type: binary

type: version
unfixedAffected

 

fence-agents-nutanix-ahv

package type: binary

type: version
unfixedAffected

 

fence-agents-openstack

package type: binary

type: version
unfixedAffected

 

fence-agents-redfish

package type: binary

type: version
unfixedAffected

 

fence-agents-rhevm

package type: binary

type: version
unfixedAffected

 

fence-agents-rsa

package type: binary

type: version
unfixedAffected

 

fence-agents-rsb

package type: binary

type: version
unfixedAffected

 

fence-agents-sbd

package type: binary

type: version
unfixedAffected

 

fence-agents-scsi

package type: binary

type: version
unfixedAffected

 

fence-agents-virsh

package type: binary

type: version
unfixedAffected

 

fence-agents-vmware-rest

package type: binary

type: version
unfixedAffected

 

fence-agents-vmware-soap

package type: binary

type: version
unfixedAffected

 

fence-agents-wti

package type: binary

type: version
unfixedAffected

 

fence-agents-zvm

package type: binary

type: version
unfixedAffected

 

fence-agents

package type: source

type: version

tag: rhel-8-including-unpatched:6c8786b8-5912-31dd-5e36-8821e3eaebdc

redhat:9
CVE-2026-26007

redhat-vex

OR

unfixedAffected

 

fence-agents-aliyun

package type: binary

type: version
unfixedAffected

 

fence-agents-all

package type: binary

type: version
unfixedAffected

 

fence-agents-amt-ws

package type: binary

type: version
unfixedAffected

 

fence-agents-apc

package type: binary

type: version
unfixedAffected

 

fence-agents-apc-snmp

package type: binary

type: version
unfixedAffected

 

fence-agents-aws

package type: binary

type: version
unfixedAffected

 

fence-agents-azure-arm

package type: binary

type: version
unfixedAffected

 

fence-agents-bladecenter

package type: binary

type: version
unfixedAffected

 

fence-agents-brocade

package type: binary

type: version
unfixedAffected

 

fence-agents-cisco-mds

package type: binary

type: version
unfixedAffected

 

fence-agents-cisco-ucs

package type: binary

type: version
unfixedAffected

 

fence-agents-common

package type: binary

type: version
unfixedAffected

 

fence-agents-compute

package type: binary

type: version
unfixedAffected

 

fence-agents-drac5

package type: binary

type: version
unfixedAffected

 

fence-agents-eaton-snmp

package type: binary

type: version
unfixedAffected

 

fence-agents-emerson

package type: binary

type: version
unfixedAffected

 

fence-agents-eps

package type: binary

type: version
unfixedAffected

 

fence-agents-gce

package type: binary

type: version
unfixedAffected

 

fence-agents-heuristics-ping

package type: binary

type: version
unfixedAffected

 

fence-agents-hpblade

package type: binary

type: version
unfixedAffected

 

fence-agents-ibm-powervs

package type: binary

type: version
unfixedAffected

 

fence-agents-ibm-vpc

package type: binary

type: version
unfixedAffected

 

fence-agents-ibmblade

package type: binary

type: version
unfixedAffected

 

fence-agents-ifmib

package type: binary

type: version
unfixedAffected

 

fence-agents-ilo-moonshot

package type: binary

type: version
unfixedAffected

 

fence-agents-ilo-mp

package type: binary

type: version
unfixedAffected

 

fence-agents-ilo-ssh

package type: binary

type: version
unfixedAffected

 

fence-agents-ilo2

package type: binary

type: version
unfixedAffected

 

fence-agents-intelmodular

package type: binary

type: version
unfixedAffected

 

fence-agents-ipdu

package type: binary

type: version
unfixedAffected

 

fence-agents-ipmilan

package type: binary

type: version
unfixedAffected

 

fence-agents-kdump

package type: binary

type: version
unfixedAffected

 

fence-agents-kubevirt

package type: binary

type: version
unfixedAffected

 

fence-agents-lpar

package type: binary

type: version
unfixedAffected

 

fence-agents-mpath

package type: binary

type: version
unfixedAffected

 

fence-agents-nutanix-ahv

package type: binary

type: version
unfixedAffected

 

fence-agents-openstack

package type: binary

type: version
unfixedAffected

 

fence-agents-redfish

package type: binary

type: version
unfixedAffected

 

fence-agents-rhevm

package type: binary

type: version
unfixedAffected

 

fence-agents-rsa

package type: binary

type: version
unfixedAffected

 

fence-agents-rsb

package type: binary

type: version
unfixedAffected

 

fence-agents-sbd

package type: binary

type: version
unfixedAffected

 

fence-agents-scsi

package type: binary

type: version
unfixedAffected

 

fence-agents-virsh

package type: binary

type: version
unfixedAffected

 

fence-agents-vmware-rest

package type: binary

type: version
unfixedAffected

 

fence-agents-vmware-soap

package type: binary

type: version
unfixedAffected

 

fence-agents-wti

package type: binary

type: version
unfixedAffected

 

fence-agents-zvm

package type: binary

type: version
unfixedAffected

 

fence-virt

package type: binary

type: version
unfixedAffected

 

fence-virtd

package type: binary

type: version
unfixedAffected

 

fence-virtd-cpg

package type: binary

type: version
unfixedAffected

 

fence-virtd-libvirt

package type: binary

type: version
unfixedAffected

 

fence-virtd-multicast

package type: binary

type: version
unfixedAffected

 

fence-virtd-serial

package type: binary

type: version
unfixedAffected

 

fence-virtd-tcp

package type: binary

type: version
unfixedAffected

 

ha-cloud-support

package type: binary

type: version
unfixedAffected

 

fence-agents

package type: source

type: version

tag: rhel-9-including-unpatched:0daa01c5-69be-59cd-61ab-f12589bb955e

Data Sources

  • RedHat Enterprise Linux CSAF VEX

    redhat-vex

VulsFutureVuls|GitHub Logo IconGitHub