Python's cryptography library prior to 46.0.5 accepted elliptic curve public keys from small-order subgroups without validation. An attacker supplying such a weak key can leak bits of the victim's private key during ECDH negotiation or forge signatures on the subgroup.
Random Memories
Python's cryptography library prior to 46.0.5 accepted elliptic curve public key