Need fix for - CVE-2024-23342 or PYSEC-2026-1325 in ecdsa 0.19.2

Open
#381 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
35/100
Issue type
Bug
Clarity
Needs clarification
Activity status
Active
Tech stack
python

Research direction

Start by reviewing CVE-2024-23342 and PYSEC-2026-1325 against the ecdsa 0.19.2 release and its documented affected behavior. The issue names no files, tests, or entry points, so identify the vulnerable area and its expected safe behavior before making a change. Done means the vulnerability is addressed and regression coverage and release guidance are established.

Written by the indexing model from the issue text.

Description

Hey team, we are beneficiaries of the OSS python package, we would like to highlight that the latest version 0.19.2 has a security vulnerability -
CVE-2024-23342 or PYSEC-2026-1325, can we get a fix for this one?

Dominant language
Python
Stars
973
Forks
343
PR merge metrics
No merged PRs in 30d

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from tlsfuzzer/python-ecdsa

All issues in tlsfuzzer/python-ecdsa

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.