Timing Attack Affecting cryptography package, versions [44.0.0, 50.0.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.18% (8th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-CRYPTOGRAPHY-18516621
  • published4 Aug 2026
  • disclosed4 Aug 2026
  • creditX1AOxiang

Introduced: 4 Aug 2026

NewCVE-2026-69247  (opens in a new tab)
CWE-208  (opens in a new tab)

How to fix?

Upgrade cryptography to version 50.0.0 or higher.

Overview

Affected versions of this package are vulnerable to Timing Attack in the pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime functions. An attacker can obtain sensitive information about the outcome of RSA decryption operations by submitting crafted EnvelopedData and analyzing error messages or timing differences. This can be exploited to perform adaptive chosen ciphertext attacks against the content-encryption key.

Note: This is only exploitable if the application automatically decrypts untrusted EnvelopedData matching the victim certificate and provides adaptive responses at high volume, such as in S/MIME gateways or mail filters, and if the linked cryptographic library lacks implicit rejection (e.g., OpenSSL 3.0/3.1, LibreSSL, BoringSSL).

CVSS Base Scores

version 4.0
version 3.1