AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-10903

HIGH · CVSS 7.5 EPSS 3.20% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-07-30 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2018-10903
Severity
HIGH
CVSS
7.5
EPSS
3.20%

Original NVD Description

A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an invalid payload with a shortened tag (e.g. 1 byte) such that they would have a 1 in 256 chance of passing the MAC check. GCM tag forgeries can cause key leakage.