—
PYSEC-2026-3028
pyquorum: Timing side‑channel in mul_mod
Quick fix
PYSEC-2026-3028 — pyquorum: upgrade to the fixed version with the command below.
pip install --upgrade 'pyquorum>=0.2.1'Details
### Impact The `mul_mod` function implements multiplication via a binary expansion loop whose execution time depends on the Hamming weight of the second operand (the exponent). An attacker who can measure the time of secret‑sharing operations (e.g., via a remote service) could progressively recover the values of shares, ultimately leading to secret reconstruction.
### Patches https://github.com/svvqt/pyquorum/releases/tag/v0.2.1
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/svvqt/pyquorum/security/advisories/GHSA-7r92-3jgr-r65q[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-44368[ADVISORY]
- https://github.com/svvqt/pyquorum/commit/1e9ac41dd3c305c13d7a6b7d227bf325be82d730[WEB]
- https://github.com/svvqt/pyquorum[PACKAGE]
- https://github.com/svvqt/pyquorum/releases/tag/v0.2.1[WEB]
- https://pypi.org/project/pyquorum[PACKAGE]
- https://github.com/advisories/GHSA-7r92-3jgr-r65q[ADVISORY]