CVE-2026-26007 | pyca cryptography up to 46.0.4 data authenticity (GHSA-r6ph-v2qm-q3c2 / Nessus ID 298585)
A vulnerability was found in pyca cryptography up to 46.0.4. It has been classified as problematic. This issue affects the function EllipticCurvePublicNumbers.public_key/EllipticCurvePublicNumbers.public_key/load_der_public_key/load_pem_public_key. The manipulation leads to insufficient verification of data authenticity.
This vulnerability is documented as CVE-2026-26007. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.