CVE-2026-69247: CWE-208: Observable Timing Discrepancy in pyca cryptography
A timing discrepancy vulnerability exists in the pyca cryptography package versions 44.0.0 up to but not including 50.0.0. The issue affects the pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime functions, which leak information about the RSA decrypted key length through observable timing and error differences. This leakage can enable a Bleichenbacher oracle attack against the content-encryption key if an application decrypts attacker-supplied EnvelopedData and reflects the outcome. The vulnerability requires a service that automatically decrypts untrusted EnvelopedData matching the victim certificate and responds adaptively at high volume. The issue is fixed in version 50.0.0.
AI Analysis
Technical Summary
The pyca cryptography package versions >=44.0.0 and <50.0.0 contain a vulnerability where the pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime functions reveal the outcome of decrypting a RecipientInfo's encryptedKey in distinguishable ways, including timing differences. This allows an attacker to perform a Bleichenbacher oracle attack on the content-encryption key by analyzing the decryption responses. The vulnerability arises because invalid RSA padding, valid padding with incorrect key length, correct length with wrong key, and the real key each produce different failure or success signals. This is particularly exploitable when the underlying cryptographic library lacks implicit rejection of invalid padding, such as OpenSSL 3.0/3.1, LibreSSL, and BoringSSL. Exploitation requires a service that auto-decrypts untrusted EnvelopedData and responds adaptively, such as an S/MIME gateway or mail filter. The vulnerability is resolved in pyca cryptography version 50.0.0.
Potential Impact
An attacker can exploit this vulnerability to perform a Bleichenbacher oracle attack against the content-encryption key used in RSA PKCS#1 v1.5 decryption within the affected pyca cryptography versions. This could lead to the recovery of sensitive cryptographic keys if the application decrypts attacker-controlled EnvelopedData and reveals decryption outcomes. The impact is significant in environments where such auto-decryption services exist and respond adaptively, potentially compromising confidentiality of encrypted communications.
Mitigation Recommendations
This vulnerability is fixed in pyca cryptography version 50.0.0. Users should upgrade to version 50.0.0 or later to remediate this issue. No official patch or temporary fix is indicated other than upgrading. Since this is not a cloud service, remediation depends on user action to update the package. Patch status is confirmed by the vendor advisory stating the fix is in version 50.0.0.
CVE-2026-69247: CWE-208: Observable Timing Discrepancy in pyca cryptography
Description
A timing discrepancy vulnerability exists in the pyca cryptography package versions 44.0.0 up to but not including 50.0.0. The issue affects the pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime functions, which leak information about the RSA decrypted key length through observable timing and error differences. This leakage can enable a Bleichenbacher oracle attack against the content-encryption key if an application decrypts attacker-supplied EnvelopedData and reflects the outcome. The vulnerability requires a service that automatically decrypts untrusted EnvelopedData matching the victim certificate and responds adaptively at high volume. The issue is fixed in version 50.0.0.
CVSS v4.0
Score 8.2high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The pyca cryptography package versions >=44.0.0 and <50.0.0 contain a vulnerability where the pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime functions reveal the outcome of decrypting a RecipientInfo's encryptedKey in distinguishable ways, including timing differences. This allows an attacker to perform a Bleichenbacher oracle attack on the content-encryption key by analyzing the decryption responses. The vulnerability arises because invalid RSA padding, valid padding with incorrect key length, correct length with wrong key, and the real key each produce different failure or success signals. This is particularly exploitable when the underlying cryptographic library lacks implicit rejection of invalid padding, such as OpenSSL 3.0/3.1, LibreSSL, and BoringSSL. Exploitation requires a service that auto-decrypts untrusted EnvelopedData and responds adaptively, such as an S/MIME gateway or mail filter. The vulnerability is resolved in pyca cryptography version 50.0.0.
Potential Impact
An attacker can exploit this vulnerability to perform a Bleichenbacher oracle attack against the content-encryption key used in RSA PKCS#1 v1.5 decryption within the affected pyca cryptography versions. This could lead to the recovery of sensitive cryptographic keys if the application decrypts attacker-controlled EnvelopedData and reveals decryption outcomes. The impact is significant in environments where such auto-decryption services exist and respond adaptively, potentially compromising confidentiality of encrypted communications.
Mitigation Recommendations
This vulnerability is fixed in pyca cryptography version 50.0.0. Users should upgrade to version 50.0.0 or later to remediate this issue. No official patch or temporary fix is indicated other than upgrading. Since this is not a cloud service, remediation depends on user action to update the package. Patch status is confirmed by the vendor advisory stating the fix is in version 50.0.0.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-03T19:54:19.852Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a710cc4bf32cb7a34490873
Added to database: 08/03/2026, 21:48:52 UTC
Last enriched: 08/03/2026, 22:03:04 UTC
Last updated: 08/03/2026, 22:03:04 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.