CVE-2020-25659: Cryptography.io Cryptography

Medium severity, CVSS 5.9. EPSS: 2.5% chance of exploitation in the next 30 days.

python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.

Affected products

  • Cryptography.io Cryptography: version 3.2 only
  • Oracle Communications Cloud Native Core Network Function Cloud Native Environment: version 1.10.0 only

Published 2021-01-11. Last modified 2026-06-17.