---
id: CVE-2023-52323
aliases:
  - GHSA-j225-cvw7-qrx7
  - PYSEC-2024-3
  - PYSEC-2026-1811
title: PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption
summary: PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'
vendor: pycryptodomex
product: pycryptodomex
ecosystem: pip
affected:
  - pycryptodomex < 3.19.1
  - pycryptodome < 3.19.1
patched:
  - pycryptodomex 3.19.1
  - pycryptodome 3.19.1
published: '2024-01-05'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:04.975951117Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-j225-cvw7-qrx7'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-52323'
  - url: >-
      https://github.com/Legrandin/pycryptodome/commit/0deea1bfe1489e8c80d2053bbb06a1aa0b181ebd
  - url: 'https://github.com/Legrandin/pycryptodome'
  - url: 'https://github.com/Legrandin/pycryptodome/blob/master/Changelog.rst'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/pycryptodomex/PYSEC-2024-3.yaml
  - url: 'https://pypi.org/project/pycryptodomex/#history'
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-52323.json
  - url: 'https://access.redhat.com/security/cve/CVE-2023-52323'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2257028'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2023-52323'
  - url: 'https://access.redhat.com/errata/RHSA-2024:1057'
  - url: 'https://access.redhat.com/errata/RHSA-2024:2010'
  - url: 'https://access.redhat.com/errata/RHSA-2024:2968'
  - url: 'https://access.redhat.com/errata/RHBA-2024:1398'
  - url: 'https://access.redhat.com/errata/RHBA-2024:1114'
  - url: 'https://access.redhat.com/errata/RHSA-2024:1155'
  - url: 'https://access.redhat.com/errata/RHBA-2024:1091'
  - url: 'https://access.redhat.com/errata/RHBA-2024:1137'
  - url: 'https://access.redhat.com/errata/RHSA-2024:2132'
  - url: 'https://access.redhat.com/errata/RHSA-2024:2952'
tags:
  - osv
  - pip
  - csaf
  - vex
  - red-hat
epss: 0.00618
epssPercentile: 0.47377
cwe:
  - CWE-203
scores:
  osv: 5.3
  vendor: 5.9
ingestedAt: '2026-07-08T18:25:50.513Z'
---

## Overview

PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.

## Affected packages

- `pycryptodomex < 3.19.1`
- `pycryptodome < 3.19.1`

## Remediation

Upgrade to a patched release:

- `pycryptodomex 3.19.1`
- `pycryptodome 3.19.1`

## Vendor advisories

- **RHSA-2024:1057** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.4 for RHEL 8, Red Hat Ansible Automation Platform 2.4 for RHEL 9 · released 2024-02-29 · [advisory](https://access.redhat.com/errata/RHSA-2024:1057)
- **RHSA-2024:2010** · Red Hat · fixed in: Red Hat Satellite 6.15 for RHEL 8 · released 2024-04-23 · [advisory](https://access.redhat.com/errata/RHSA-2024:2010)
- **RHSA-2024:2968** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8), Red Hat Enterprise Linux HighAvailability (v. 8), Red Hat Enterprise Linux ResilientStorage (v. 8) · released 2024-05-22 · [advisory](https://access.redhat.com/errata/RHSA-2024:2968)
- **RHBA-2024:1398** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.4), Red Hat Enterprise Linux AppStream E4S (v.8.4), Red Hat Enterprise Linux AppStream TUS (v.8.4), Red Hat Enterprise Linux High Availability AUS (v.8.4), Red Hat Enterprise Linux HighAvailability E4S (v.8.4), Red Hat Enterprise Linux HighAvailability TUS (v.8.4) · released 2024-03-19 · [advisory](https://access.redhat.com/errata/RHBA-2024:1398)
- **RHBA-2024:1114** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.8.6), Red Hat Enterprise Linux High Availability EUS (v.8.6), Red Hat Enterprise Linux Resilient Storage EUS (v.8.6) · released 2024-03-05 · [advisory](https://access.redhat.com/errata/RHBA-2024:1114)
- **RHSA-2024:1155** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.0), Red Hat Enterprise Linux High Availability EUS (v.9.0), Red Hat Enterprise Linux Resilient Storage EUS (v.9.0) · released 2024-03-05 · [advisory](https://access.redhat.com/errata/RHSA-2024:1155)
- **RHBA-2024:1091** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.2), Red Hat Enterprise Linux High Availability EUS (v.9.2), Red Hat Enterprise Linux Resilient Storage EUS (v.9.2) · released 2024-03-05 · [advisory](https://access.redhat.com/errata/RHBA-2024:1091)
- **RHBA-2024:1137** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux High Availability (v. 9), Red Hat Enterprise Linux Resilient Storage (v. 9) · released 2024-03-05 · [advisory](https://access.redhat.com/errata/RHBA-2024:1137)
- **RHSA-2024:2132** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux HighAvailability (v. 9), Red Hat Enterprise Linux ResilientStorage (v. 9) · released 2024-04-30 · [advisory](https://access.redhat.com/errata/RHSA-2024:2132)
- **RHSA-2024:2952** · Red Hat · fixed in: Red Hat Enterprise Linux HighAvailability (v. 8), Red Hat Enterprise Linux ResilientStorage (v. 8) · released 2024-05-22 · [advisory](https://access.redhat.com/errata/RHSA-2024:2952)
- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 7, Red Hat Storage 3 · no fix planned: Red Hat Enterprise Linux 7, Red Hat Storage 3 · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-52323.json)
