PYSEC-2026-1595

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/m2crypto/PYSEC-2026-1595.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-1595
Aliases
Published
2026-07-07T11:45:31Z
Modified
2026-07-07T17:46:56Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
m2crypto Bleichenbacher timing attack - incomplete fix for CVE-2020-25657
Details

A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

References

Affected packages

PyPI / m2crypto

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
0.40.1

Affected versions

0.*
0.11
0.13
0.15
0.16
0.17
0.18
0.18.1
0.18.2
0.19
0.19.1
0.20beta1
0.20
0.20.1
0.20.2
0.21
0.21.1
0.22.3
0.22.4
0.22.5
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.26.2
0.26.3
0.26.4
0.27.0
0.28.0
0.28.1
0.28.2
0.29.0
0.30.0
0.30.1
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.1
0.35.2
0.36.0
0.37.0
0.37.1
0.38.0
0.39.0
0.40.0
0.40.1

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/m2crypto/PYSEC-2026-1595.yaml"