SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-69247

HIGH · CVSS 8.2 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-03 · Last synced 2026-09-02

CyberRota Analysis

AI-Generated

The vulnerability affects the cryptography package in Python versions 44.0.0 to 50.0.0, specifically in the pkcs7_decrypt functions, which inadvertently expose the length of decrypted RSA keys through distinguishable outcomes and timing variations. This flaw enables attackers to exploit a Bleichenbacher oracle, potentially allowing them to recover content-encryption keys from applications that auto-decrypt untrusted EnvelopedData, such as S/MIME gateways or mail filters. Organizations utilizing these affected Python versions, particularly those implementing cryptographic operations in email or data processing, should prioritize upgrading to version 50.0.0 or later to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-69247
Severity
HIGH
CVSS
8.2
EPSS
0.18%
Oracle OpenSSL

Original NVD Description

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the exact length recovered from the RSA operation. The same distinction was also observable by timing. An application that decrypts attacker-supplied EnvelopedData and reflects the outcome gives the attacker a Bleichenbacher oracle against the content-encryption key. Decryption ran as RSA PKCS#1 v1.5 decrypt of encryptedKey, build an AES cipher from the result, then AES-CBC decrypt and PKCS#7 unpad. Invalid RSA padding, a valid padding with a bad key length, a correct length with a wrong key, and the real key each failed or succeeded differently. Case 1 is reachable only where the linked library lacks implicit rejection: OpenSSL 3.0 and 3.1, LibreSSL, and BoringSSL. Exploitation requires a service that auto-decrypts untrusted EnvelopedData matching the victim certificate and answers adaptively at high volume, such as an S/MIME gateway or mail filter. This issue is fixed in 50.0.0.