Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-26007

29
FAUCET Score

CVE-2026-26007 describes a vulnerability in the cryptography Python package (versions prior to 46.0.5) where public key validation functions fail to verify that Elliptic Curve Cryptography (ECC) points belong to the expected prime-order subgroup, specifically impacting SECT curves. This oversight allows attackers to provide public keys from small-order subgroups, potentially leading to information leakage of private keys during ECDH key negotiation or enabling signature forgery in ECDSA. Rated Medium severity (CVSS 6.5), the vulnerability has a network attack vector and low attack complexity, requiring user interaction (UI:R). A successful exploit could result in high confidentiality impact (C:H) by revealing private key information, but no integrity or availability impact. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. While community discussion is minimal, it includes mentions of a fix being implemented on GitHub.

Impacted Technologies

VendorProductVersion(s)CPE
< 46.0.5CPE matchmatch criteria
cpe:2.3:a:cryptography.io:cryptography:*:*:*:*:*:python:*:*

CVSS Data

CVSS version used by this source: 4.0

8.2HIGH

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.34%
Probability of exploitation in next 30 days
EPSS Percentile
26.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0034 is in the 27th percentile among its peer group of 26,221 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (59)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: cryptographyFixed in: 46.0.5
redhatpatch availablevia redhat_api
Product: Red Hat Discovery 2Fixed in: discovery/discovery-server-rhel9:sha256:cdf9b1062c961f67ee4f5dd3e23b26420517f884a51d2034efacff6847d47b5f
View patch
ubuntupatch availablevia ubuntu_usn
Product: python-cryptography (focal)Fixed in: 2.8-3ubuntu0.3+esm2
ubuntupatch availablevia ubuntu_usn
Product: python-cryptography (xenial)Fixed in: 1.2.3-1ubuntu0.3+esm3
ubuntupatch availablevia ubuntu_usn
Product: python-cryptography (jammy)Fixed in: 3.4.8-1ubuntu2.3
ubuntupatch availablevia ubuntu_usn
Product: python-cryptography (noble)Fixed in: 41.0.7-4ubuntu0.3
ubuntupatch availablevia ubuntu_usn
Product: python-cryptography (questing)Fixed in: 43.0.0-1ubuntu1.1
ubuntupatch availablevia ubuntu_usn
Product: python-cryptography (bionic)Fixed in: 2.1.4-1ubuntu1.4+esm3
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-26/hub-rhel9
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-26/lightspeed-chatbot-rhel9
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-26/lightspeed-rhel9
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-26/mcp-tools-rhel9
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform/automation-dashboard-rhel9
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-tech-preview/automation-dashboard-rhel9
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: automation-controller
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform Ansible Core 2Fixed in: ansible-automation-platform/ee-minimal-rhel8
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform Ansible Core 2Fixed in: ansible-automation-platform-tech-preview/ee-minimal-rhel8
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform Ansible Core 2Fixed in: ansible-automation-platform-tech-preview/ee-minimal-rhel9
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: fence-agents
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: fence-agents
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-feature-server-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-kserve-storage-initializer-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-llama-stack-core-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-trustyai-ragas-lls-provider-dsp-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat Quay 3Fixed in: quay/quay-rhel8
redhatno patchvia redhat_api
Product: Red Hat Quay 3Fixed in: quay/quay-rhel9
redhatno patchvia redhat_api
Product: Red Hat Satellite 6Fixed in: satellite/foreman-mcp-server-rhel9
redhatno patchvia redhat_api
Product: Red Hat Satellite 6Fixed in: satellite/iop-advisor-engine-rhel9
redhatno patchvia redhat_api
Product: Red Hat Satellite 6Fixed in: satellite/iop-host-inventory-rhel9
redhatno patchvia redhat_api
Product: Red Hat Satellite 6Fixed in: satellite/iop-insights-engine-rhel9
redhatno patchvia redhat_api
Product: Red Hat Satellite 6Fixed in: satellite/iop-vmaas-rhel9
redhatno patchvia redhat_api
Product: Red Hat Trusted Artifact SignerFixed in: rhtas/model-transparency-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9
redhatno patchvia redhat_api
Product: OpenShift LightspeedFixed in: openshift-lightspeed/lightspeed-ocp-rag-rhel9
redhatno patchvia redhat_api
Product: OpenShift LightspeedFixed in: openshift-lightspeed/lightspeed-service-api-rhel9
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-25/ee-supported-rhel8
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-25/lightspeed-rhel8
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-26/controller-rhel9
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-26/eda-controller-rhel9
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-26/ee-supported-rhel9
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-26/gateway-rhel9

Vendor Advisories (4)

ubuntuUSN-8087-3

python-cryptography vulnerability

Apr 28, 2026
ubuntuUSN-8087-1

python-cryptography vulnerability

Mar 12, 2026
redhatCVE-2026-26007Important

cryptography: cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves

Feb 10, 2026
pipGHSA-r6ph-v2qm-q3c2high

cryptography Vulnerable to a Subgroup Attack Due to Missing Subgroup Validation for SECT Curves

Feb 10, 2026

References

access.redhat.com / errata/RHSA-2026:10184
access.redhat.com / errata/RHSA-2026:12176
access.redhat.com / errata/RHSA-2026:13512
access.redhat.com / errata/RHSA-2026:13545
access.redhat.com / errata/RHSA-2026:13553
access.redhat.com / errata/RHSA-2026:13672
access.redhat.com / errata/RHSA-2026:19355
access.redhat.com / errata/RHSA-2026:21431
access.redhat.com / errata/RHSA-2026:21517
access.redhat.com / errata/RHSA-2026:22330
access.redhat.com / errata/RHSA-2026:22993
access.redhat.com / errata/RHSA-2026:2694
access.redhat.com / errata/RHSA-2026:5168
access.redhat.com / errata/RHSA-2026:5665
access.redhat.com / errata/RHSA-2026:6308
access.redhat.com / errata/RHSA-2026:6309
access.redhat.com / errata/RHSA-2026:6497
access.redhat.com / errata/RHSA-2026:6567
access.redhat.com / errata/RHSA-2026:6568
access.redhat.com / errata/RHSA-2026:7295
access.redhat.com / security/cve/CVE-2026-26007
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-26007.json
openwall.com / lists/oss-security/2026/02/10/4
Mailing ListThird Party Advisory
github.com / pyca/cryptography/commit/0eebb9dbb6343d9bc1d91e5a2482ed4e054a6d8c
Patch
github.com / pyca/cryptography/security/advisories/GHSA-r6ph-v2qm-q3c2
Vendor Advisory