CVE-2026-69247: CWE-208: Observable Timing Discrepancy in pyca cryptography
A timing discrepancy vulnerability exists in the pyca cryptography package versions 44.0.0 up to but not including 50.0.0. The issue involves the pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime functions which leak information about the length of the decrypted RSA encryptedKey through observable timing differences and distinct error messages. This leakage can be exploited as a Bleichenbacher oracle against the content-encryption key if an application decrypts attacker-supplied EnvelopedData and reflects the outcome. The vulnerability is fixed in version 50.0.0.
AI Analysis
Technical Summary
The pyca cryptography package versions >=44.0.0 <50.0.0 contain a vulnerability where the decryption functions for PKCS#7 EnvelopedData leak information about the decrypted RSA encryptedKey via timing and error message discrepancies. Specifically, the functions pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime report different outcomes for invalid RSA padding, valid padding with incorrect key length, correct length with wrong key, and the real key. This creates a Bleichenbacher oracle that can be exploited if a service automatically decrypts untrusted EnvelopedData matching the victim certificate and responds adaptively at high volume, such as an S/MIME gateway or mail filter. The issue arises when the underlying cryptographic library (OpenSSL 3.0/3.1, LibreSSL, BoringSSL) does not implicitly reject certain padding cases. The vulnerability is resolved in version 50.0.0 of the cryptography package.
Potential Impact
An attacker who can supply EnvelopedData to a vulnerable service that decrypts and reflects the result can use the timing and error message differences to perform a Bleichenbacher attack. This can lead to disclosure of the content-encryption key, potentially allowing decryption of protected data. The vulnerability requires a high-volume adaptive response service and is limited to environments using affected versions of the cryptography package with certain underlying TLS libraries. No known exploits in the wild have been reported.
Mitigation Recommendations
Upgrade the pyca cryptography package to version 50.0.0 or later, where this vulnerability is fixed. If upgrading is not immediately possible, avoid decrypting untrusted EnvelopedData or ensure that the service does not leak decryption outcome details through timing or error messages. Since this is not a cloud service, remediation depends on applying the official fix.
CVE-2026-69247: CWE-208: Observable Timing Discrepancy in pyca cryptography
Description
A timing discrepancy vulnerability exists in the pyca cryptography package versions 44.0.0 up to but not including 50.0.0. The issue involves the pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime functions which leak information about the length of the decrypted RSA encryptedKey through observable timing differences and distinct error messages. This leakage can be exploited as a Bleichenbacher oracle against the content-encryption key if an application decrypts attacker-supplied EnvelopedData and reflects the outcome. The vulnerability is fixed in version 50.0.0.
CVSS v4.0
Score 8.2high
Affected software
pyca
cryptography
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The pyca cryptography package versions >=44.0.0 <50.0.0 contain a vulnerability where the decryption functions for PKCS#7 EnvelopedData leak information about the decrypted RSA encryptedKey via timing and error message discrepancies. Specifically, the functions pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime report different outcomes for invalid RSA padding, valid padding with incorrect key length, correct length with wrong key, and the real key. This creates a Bleichenbacher oracle that can be exploited if a service automatically decrypts untrusted EnvelopedData matching the victim certificate and responds adaptively at high volume, such as an S/MIME gateway or mail filter. The issue arises when the underlying cryptographic library (OpenSSL 3.0/3.1, LibreSSL, BoringSSL) does not implicitly reject certain padding cases. The vulnerability is resolved in version 50.0.0 of the cryptography package.
Potential Impact
An attacker who can supply EnvelopedData to a vulnerable service that decrypts and reflects the result can use the timing and error message differences to perform a Bleichenbacher attack. This can lead to disclosure of the content-encryption key, potentially allowing decryption of protected data. The vulnerability requires a high-volume adaptive response service and is limited to environments using affected versions of the cryptography package with certain underlying TLS libraries. No known exploits in the wild have been reported.
Mitigation Recommendations
Upgrade the pyca cryptography package to version 50.0.0 or later, where this vulnerability is fixed. If upgrading is not immediately possible, avoid decrypting untrusted EnvelopedData or ensure that the service does not leak decryption outcome details through timing or error messages. Since this is not a cloud service, remediation depends on applying the official fix.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-03T19:54:19.852Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a710cc4bf32cb7a34490873
Added to database: 08/03/2026, 21:48:52 UTC
Last enriched: 08/11/2026, 18:37:56 UTC
Last updated: 09/17/2026, 22:01:37 UTC
Views: 66
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.