{"id":"CVE-2021-39182","aliases":["GHSA-35m5-8cvj-8783","PYSEC-2021-385"],"title":"Improper hashing in enrocrypt","summary":"Improper hashing in enrocrypt","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","vendor":"enrocrypt","product":"enrocrypt","ecosystem":"pip","affected":["enrocrypt < 1.1.4"],"patched":["enrocrypt 1.1.4"],"published":"2021-11-10","updated":"2026-07-08","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-35m5-8cvj-8783","references":[{"url":"https://github.com/Morgan-Phoenix/EnroCrypt/security/advisories/GHSA-35m5-8cvj-8783"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-39182"},{"url":"https://github.com/Morgan-Phoenix/EnroCrypt/commit/e652d56ac60eadfc26489ab83927af13a9b9d8ce"},{"url":"https://github.com/Morgan-Phoenix/EnroCrypt"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/enrocrypt/PYSEC-2021-385.yaml"}],"tags":["osv","pip"],"epss":0.00562,"epssPercentile":0.45537,"ingestedAt":"2026-07-08T18:25:44.813Z","slug":"CVE-2021-39182","body":"## Overview\n\n### Impact\nThe vulnerability is we used MD5 hashing Algorithm In our hashing file. If anyone who is a beginner(and doesn't know about hashes)  can face problems as MD5 is considered a Insecure Hashing Algorithm. \n\n### Patches\nThe vulnerability is patched in v1.1.4 of the product, the users can upgrade to version 1.1.4.\n\n### Workarounds\nIf u specifically want a version and don't want to upgrade, you can remove the `MD5` hashing function from the file `hashing.py` and this vulnerability will be gone\n\n### References\nhttps://www.cybersecurity-help.cz/vdb/cwe/916/\nhttps://www.cybersecurity-help.cz/vdb/cwe/327/\nhttps://www.cybersecurity-help.cz/vdb/cwe/328/\nhttps://www.section.io/engineering-education/what-is-md5/\nhttps://www.johndcook.com/blog/2019/01/24/reversing-an-md5-hash/\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [**Enrocrypt's Official Repo**](http://www.github.com/Morgan-Phoenix/EnroCrypt)\n* Create a Discussion in  [**Enrocrypt's Official Repo**](http://www.github.com/Morgan-Phoenix/EnroCrypt)\n\n\n## Affected packages\n\n- `enrocrypt < 1.1.4`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `enrocrypt 1.1.4`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}