---
id: CVE-2013-2228
aliases:
  - GHSA-gq26-cpq6-w85r
  - PYSEC-2026-748
title: SaltStack RSA Key Generation allows remote users to decrypt communications
summary: SaltStack RSA Key Generation allows remote users to decrypt communications
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: salt
product: salt
ecosystem: pip
affected:
  - salt < 0.15.1
patched:
  - salt 0.15.1
published: '2022-05-05'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-gq26-cpq6-w85r'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2013-2228'
  - url: 'https://bugs.gentoo.org/show_bug.cgi?id=CVE-2013-2228'
  - url: 'https://bugzilla.suse.com/show_bug.cgi?id=CVE-2013-2228'
  - url: 'https://exchange.xforce.ibmcloud.com/vulnerabilities/85372'
  - url: 'https://security-tracker.debian.org/tracker/CVE-2013-2228'
  - url: 'http://www.openwall.com/lists/oss-security/2013/07/01/1'
  - url: 'http://www.securityfocus.com/bid/60868'
  - url: 'http://www.securitytracker.com/id/1028717'
tags:
  - osv
  - pip
epss: 0.01961
epssPercentile: 0.79197
ingestedAt: '2026-07-08T18:25:49.765Z'
---

## Overview

SaltStack RSA Key Generation allows remote users to decrypt communications

## Affected packages

- `salt < 0.15.1`

## Remediation

Upgrade to a patched release:

- `salt 0.15.1`
