CVE-2026-21895

ADVISORY - github

Summary

When creating a RSA private key from its components, the construction panics, instead of returning an error, when one of the primes is 1.

Discovered by Christian Reitter from Radically Open Security during a security review for Proton AG.

EPSS Score: 0.00055 (0.174)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Improper Check or Handling of Exceptional Conditions

ADVISORY - github

Improper Check or Handling of Exceptional Conditions

ADVISORY - redhat

Improper Check or Handling of Exceptional Conditions


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in