VDB
Sign up
MEDIUM4.7

PYSEC-2026-1066

wolfCrypt leaks cryptographic information via timing side channel

Quick fix

PYSEC-2026-1066 — wolfcrypt: upgrade to the fixed version with the command below.

pip install --upgrade 'wolfcrypt>=4.1.0'

Details

wolfSSL and wolfCrypt 4.0.0 and earlier (when configured without `--enable-fpecc`, `--enable-sp`, or` --enable-sp-math`) contain a timing side channel in ECDSA signature generation. This allows a local attacker, able to precisely measure the duration of signature operations, to infer information about the nonces used and potentially mount a lattice attack to recover the private key used. The issue occurs because ecc.c scalar multiplication might leak the bit length.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/wolfcrypt
Introduced in: 0Fixed in: 4.1.0
Fixpip install --upgrade 'wolfcrypt>=4.1.0'

References