{"id":"CVE-2026-69247","title":"cryptography is a package designed to expose cryptographic primitives and recipes to Python developers","summary":"cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a Recipien…","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-208","CWE-209"],"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","affected":["enterprise_linux 10","enterprise_linux 9","hardened_images"],"patched":["hardened_images"],"published":"2026-08-03","updated":"2026-09-10","sourceUpdated":"2026-09-10T20:36:14.340","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-69247","references":[{"url":"https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f","label":"security-advisories@github.com"},{"url":"https://github.com/pyca/cryptography/pull/15369","label":"security-advisories@github.com"},{"url":"https://github.com/pyca/cryptography/security/advisories/GHSA-g6cj-pr64-35w5","label":"security-advisories@github.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-69247.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-69247"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2510835"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-69247"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69247"},{"url":"https://access.redhat.com/errata/RHSA-2026:55543"},{"url":"https://github.com/advisories/GHSA-g6cj-pr64-35w5"},{"url":"https://github.com/pyca/cryptography"}],"tags":["nvd","csaf","vex","red-hat","ghsa","pip","osv"],"epss":0.00175,"epssPercentile":0.07296,"aliases":["GHSA-g6cj-pr64-35w5","PYSEC-2026-3552"],"ecosystem":"pip","cvssSource":"vendor","ingestedAt":"2026-08-03T21:30:01.446Z","slug":"CVE-2026-69247","body":"## Overview\n\ncryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the exact length recovered from the RSA operation. The same distinction was also observable by timing. An application that decrypts attacker-supplied EnvelopedData and reflects the outcome gives the attacker a Bleichenbacher oracle against the content-encryption key. Decryption ran as RSA PKCS#1 v1.5 decrypt of encryptedKey, build an AES cipher from the result, then AES-CBC decrypt and PKCS#7 unpad. Invalid RSA padding, a valid padding with a bad key length, a correct length with a wrong key, and the real key each failed or succeeded differently. Case 1 is reachable only where the linked library lacks implicit rejection: OpenSSL 3.0 and 3.1, LibreSSL, and BoringSSL. Exploitation requires a service that auto-decrypts untrusted EnvelopedData matching the victim certificate and answers adaptively at high volume, such as an S/MIME gateway or mail filter. This issue is fixed in 50.0.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-69247)\n\nAffected packages:\n\n- `cryptography >= 44.0.0, < 50.0.0`\n\nPatched in:\n\n- `cryptography 50.0.0`\n\nSource: https://github.com/advisories/GHSA-g6cj-pr64-35w5\n\n## Vendor advisories\n\n- **RHSA-2026:55543** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-08-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:55543)\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9 · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-69247.json)","depth":"sunlit","depthScore":32,"depthScoreParts":{"impact":32.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":5444,"id":"CVE-2026-69247","ts":1788887282721,"field":"cvss","old":null,"new":"5.9"},{"seq":5443,"id":"CVE-2026-69247","ts":1788887282721,"field":"severity","old":"high","new":"medium"},{"seq":4327,"id":"CVE-2026-69247","ts":1788886396443,"field":"cvss","old":"5.9","new":null},{"seq":4326,"id":"CVE-2026-69247","ts":1788886396443,"field":"severity","old":"medium","new":"high"},{"seq":3187,"id":"CVE-2026-69247","ts":1788883133369,"field":"cvss","old":null,"new":"5.9"},{"seq":3186,"id":"CVE-2026-69247","ts":1788883133369,"field":"severity","old":"high","new":"medium"}]}