Random Memories

Python's cryptography library prior to 46.0.5 accepted elliptic curve public key

Python Medium

Python's cryptography library prior to 46.0.5 accepted elliptic curve public keys from small-order subgroups without validation. An attacker supplying such a weak key can leak bits of the victim's private key during ECDH negotiation or forge signatures on the subgroup.