python-ecdsa: DER encoding is not being verified in signatures
Published Jan 2, 2020
9.3
CRITICALCVSS 4.0
EPSS 1.53%
Description
A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could use a malleable signature to create false transactions.
Affected products
-
- Version all python-ecdsa versions before 0.13.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Red Hat | Python-Ecdsa | n/a |
|
Configuration 1
- < 0.13.3
Configuration 2
- 2.0
- 3.0
Configuration 3
Configuration 4
- 4.0
No data.
Red Hat Satellite 6.10 for RHEL 7
python-ecdsa-0:0.13.3-2.el7pc
Fixed · RHSA-2021:4702
Red Hat Satellite 6.10 for RHEL 7
python-ecdsa-0:0.13.3-2.el7pc
Fixed · RHSA-2021:4702
CloudForms Management Engine 5
python-ecdsa
Not affected
Red Hat Ceph Storage 2
python-ecdsa
Will not fix
Red Hat OpenStack Platform 10 (Newton)
python-ecdsa
Will not fix
Red Hat OpenStack Platform 13 (Queens)
python-ecdsa
Will not fix
Red Hat OpenStack Platform 14 (Rocky)
python-ecdsa
Will not fix
Red Hat OpenStack Platform 15 (Stein)
python-ecdsa
Will not fix
Red Hat Storage 3
python-ecdsa
Fix deferred
Red Hat Virtualization 4
python-ecdsa
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Satellite 6.10 for RHEL 7 | python-ecdsa-0:0.13.3-2.el7pc | Fixed | RHSA-2021:4702 |
| Red Hat Satellite 6.10 for RHEL 7 | python-ecdsa-0:0.13.3-2.el7pc | Fixed | RHSA-2021:4702 |
| CloudForms Management Engine 5 | python-ecdsa | Not affected | n/a |
| Red Hat Ceph Storage 2 | python-ecdsa | Will not fix | n/a |
| Red Hat OpenStack Platform 10 (Newton) | python-ecdsa | Will not fix | n/a |
| Red Hat OpenStack Platform 13 (Queens) | python-ecdsa | Will not fix | n/a |
| Red Hat OpenStack Platform 14 (Rocky) | python-ecdsa | Will not fix | n/a |
| Red Hat OpenStack Platform 15 (Stein) | python-ecdsa | Will not fix | n/a |
| Red Hat Storage 3 | python-ecdsa | Fix deferred | n/a |
| Red Hat Virtualization 4 | python-ecdsa | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Although Red Hat OpenStack Platform ships the flawed code, RHOSP does not actually use python-ecdsa's functionality. As such, Red Hat OpenStack Platform will not be providing a fix for python-ecdsa at this time. Red Hat CloudForms 5.9, 5.10 and 5.11 is not affected as these versions no longer ship the python-ecdsa library. Only CloudForms 5.8, which is now EOL, delivered the python-ecdsa library. Current releases of Red Hat Virtualization Manager no longer include python-ecdsa as a dependency. While it remains available in repositories as a legacy dependency, it is not installed by default and its use is not recommended. Current releases of Red Hat Satellite no longer include python-ecdsa as a dependency. While it remains available in repositories as a legacy dependency, it is not installed by default and its use is not recommended.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
AV:N/AC:L/Au:N/C:P/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 1.53% (0.01534) | 73.93th | v5 (v2026.06.15) |
| Sep 20, 2026 | 1.53% (0.01534) | 73.67th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.24% (0.00235) | 62.03th | v3 (v2023.03.01) |
| Sep 19, 2023 | 0.24% (0.00235) | 61.13th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.29% (0.00289) | 64.98th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.24% (0.00236) | 59.85th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.02% (0.01018) | 40.69th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.02% (0.01018) | 36.86th | v2 (v2022.01.01) |
| Feb 4, 2022 | 15.35% (0.15351) | 91.59th | v2 (v2022.01.01) |
| Feb 3, 2022 | 4.50% (0.04504) | 76.47th | v1 |
| Jan 6, 2022 | 4.50% (0.04504) | 76.26th | v1 |
| Jan 5, 2022 | 1.04% (0.01040) | 65.70th | v5 (v2026.06.15) |
| Apr 14, 2021 | 1.04% (0.01040) | 0.00th | v1 |
References (14)
- https://access.redhat.com/security/cve/CVE-2019-14859 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1760843 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14859 x_refsource_CONFIRMExploitIssue TrackingPatchThird Party Advisory
- https://github.com/advisories/GHSA-8qxj-f9rh-9fg2 Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/ecdsa/PYSEC-2020-163.yaml
- https://github.com/tlsfuzzer/python-ecdsa/commit/3427fa29f319b27898a28601955807abb44c0830
- https://github.com/tlsfuzzer/python-ecdsa/commit/9080d1d5ac533da0de00466aaffb49bee808bb4e
- https://github.com/tlsfuzzer/python-ecdsa/commit/b0ea52bb3aa9a16c9a4a91fdc0041edbfed10b31
- https://github.com/warner/python-ecdsa/issues/114 x_refsource_MISCExploitThird Party Advisory
- https://github.com/warner/python-ecdsa/pull/115
- https://github.com/warner/python-ecdsa/releases/tag/python-ecdsa-0.13.3 x_refsource_MISCRelease NotesThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-14859
- https://pypi.org/project/ecdsa/0.13.3 x_refsource_MISCRelease NotesThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-14859
Change history (0)
No recorded changes yet.