MEDIUM5.9
PYSEC-2026-1595
m2crypto Bleichenbacher timing attack - incomplete fix for CVE-2020-25657
Details
A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/m2crypto
Introduced in:
0No fixed version published yet for m2crypto (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-50781[ADVISORY]
- https://access.redhat.com/security/cve/CVE-2023-50781[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2254426[WEB]
- https://gitlab.com/m2crypto/m2crypto[PACKAGE]
- https://gitlab.com/m2crypto/m2crypto/-/issues/342[WEB]
- https://pypi.org/project/m2crypto[PACKAGE]
- https://github.com/advisories/GHSA-944j-8ch6-rf6x[ADVISORY]