The verify function in the Stark Bank Python ECDSA library (ecdsa-python) 2.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.
"https://github.com/pypa/advisory-database/blob/main/vulns/starkbank-ecdsa/PYSEC-2021-426.yaml"