Tlsfuzzer is a cryptographic testing and fuzzing tool that targets TLS protocol implementations and related libraries such as ECDSA, surfacing timing-channel and input-handling weaknesses that are difficult to detect through standard functional testing. The recurring vulnerability classes—including covert timing channels, improper length-parameter handling, improper input validation, and observable timing discrepancies—reflect the precision required to validate both functional correctness and constant-time operation in cryptographic code. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tlsfuzzer over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33936MEDIUM The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-cu | Mar 27, 2026 | 5.3 | 21 | NO | NO |
CVE-2024-23342HIGH The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-cu | Jan 23, 2024 | 7.4 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tlsfuzzer.
Media articles that mention a CVE ID that affects a product developed by Tlsfuzzer — matched by CVE ID, not by vendor name.