CVE-2018-16869: Nettle Project Nettle
Medium severity, CVSS 5.7. EPSS: 1.5% chance of exploitation in the next 30 days.
A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run a process on the same physical core as the victim process, could use this flaw extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.
Affected products
- Nettle Project Nettle: up to and including 3.4
Published 2018-12-03. Last modified 2026-06-17.