Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-14853

25
FAUCET Score

CVE-2019-14853 describes an error-handling flaw in python-ecdsa versions prior to 0.13.3, specifically affecting the python-ecdsa_project. This vulnerability allows an unauthenticated attacker to trigger unexpected exceptions or no exceptions at all during signature decoding of malformed DER signatures. With a CVSS score of 7.5 (High), this flaw could lead to a denial of service (DoS) due to its low attack complexity and network-based vector. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.13.3CPE matchmatch criteria
cpe:2.3:a:python-ecdsa_project:python-ecdsa:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

3.7LOW

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
2.2
Impact Score
1.4
CvssVersion
3.0

Exploit Intelligence

EPSS Score
2.50%
Probability of exploitation in next 30 days
EPSS Percentile
83.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0250 is in the 70th percentile among its peer group of 51,466 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

pippatch availablevia ghsa
Product: ecdsaFixed in: 0.13.3
redhatpatch availablevia redhat_api
Product: Red Hat Satellite 6.10 for RHEL 7Fixed in: python-ecdsa-0:0.13.3-2.el7pc
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Ceph Storage 2Fixed in: python-ecdsa
redhatno patchvia redhat_api
Product: Red Hat Storage 3Fixed in: python-ecdsa
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 15 (Stein)Fixed in: python-ecdsa
redhatend of lifevia redhat_api
Product: Red Hat Virtualization 4Fixed in: python-ecdsa
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 10 (Newton)Fixed in: python-ecdsa
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 13 (Queens)Fixed in: python-ecdsa
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 14 (Rocky)Fixed in: python-ecdsa

Vendor Advisories (2)

pipGHSA-pwfw-mgfj-7g3ghigh

ecdsa Denial of Service vulnerability in signature verification and signature malleability

Oct 8, 2019
redhatCVE-2019-14853Low

python-ecdsa: Unexpected and undocumented exceptions during signature decoding

Sep 26, 2019

References

bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
github.com / warner/python-ecdsa/releases/tag/python-ecdsa-0.13.3
Release Notes
seclists.org / bugtraq/2019/Dec/33
debian.org / security/2019/dsa-4588