VDB
Sign up
MEDIUM5.9

PYSEC-2026-1595

m2crypto Bleichenbacher timing attack - incomplete fix for CVE-2020-25657

Details

A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/m2crypto
Introduced in: 0

No fixed version published yet for m2crypto (pip). Pin to a known-safe version or switch to an alternative.

References