—
PYSEC-2021-426
Quick fix
PYSEC-2021-426 — starkbank-ecdsa: upgrade to the fixed version with the command below.
pip install --upgrade 'starkbank-ecdsa>=2.0.1'Details
The verify function in the Stark Bank Python ECDSA library (ecdsa-python) 2.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/starkbank-ecdsa
Introduced in:
0Fixed in: 2.0.1Fix
pip install --upgrade 'starkbank-ecdsa>=2.0.1'