{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/cryptography--44.0.0--50.0.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-69247"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["cryptography (\u003e= 44.0.0, \u003c 50.0.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe cryptography Python library, specifically versions 44.0.0 through 49.x.x, contains a critical vulnerability in its PKCS#7 EnvelopedData decryption routines (\u003ccode\u003epkcs7_decrypt_der\u003c/code\u003e, \u003ccode\u003epkcs7_decrypt_pem\u003c/code\u003e, and \u003ccode\u003epkcs7_decrypt_smime\u003c/code\u003e). The library performs RSA PKCS#1 v1.5 decryption on an \u003ccode\u003eencryptedKey\u003c/code\u003e and subsequently decrypts the content using the resulting key.\u003c/p\u003e\n\u003cp\u003eDefenders should note that the implementation reveals distinct error messages and timing discrepancies based on whether the decryption process fails due to padding, key size mismatch, or invalid padding bytes. These side channels function as a Bleichenbacher oracle. An attacker providing untrusted \u003ccode\u003eEnvelopedData\u003c/code\u003e to a service that automatically processes and reflects these decryption outcomes (such as an S/MIME gateway or automated mail filter) can iteratively recover the content-encryption key. This is caused by a failure to comply with RFC 3218 recommendations for constant-time failure handling and uniform error responses.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the recovery of content-encryption keys used in PKCS#7 protected data. This vulnerability affects any environment utilizing the \u003ccode\u003ecryptography\u003c/code\u003e library version 44.0.0 to 49.x.x to process untrusted S/MIME or EnvelopedData content. The impact is significant for secure messaging gateways and automated data processing pipelines that interact with external, potentially malicious, encrypted payloads.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the \u003ccode\u003ecryptography\u003c/code\u003e library to version 50.0.0 or later immediately to implement RFC 3218-compliant constant-time decryption and uniform error reporting.\u003c/li\u003e\n\u003cli\u003eAudit applications utilizing \u003ccode\u003ecryptography\u003c/code\u003e to determine if they automatically decrypt and reflect errors or processing results of untrusted \u003ccode\u003eEnvelopedData\u003c/code\u003e to external entities.\u003c/li\u003e\n\u003cli\u003eRestrict the ability of automated systems to process untrusted \u003ccode\u003eEnvelopedData\u003c/code\u003e until the library patch is applied to mitigate the risk of automated oracle queries.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-03T23:41:53Z","date_published":"2026-08-03T23:41:53Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cryptography-pkcs7-oracle/","summary":"The cryptography library fails to perform constant-time operations during PKCS#7 EnvelopedData decryption, creating a Bleichenbacher oracle that allows attackers to recover content-encryption keys via error and timing analysis (CVE-2026-69247).","title":"Bleichenbacher Oracle Vulnerability in cryptography Library","url":"https://feed.craftedsignal.io/briefs/2026-08-cryptography-pkcs7-oracle/"}],"language":"en","title":"CraftedSignal Threat Feed - Cryptography (\u003e= 44.0.0, \u003c 50.0.0)","version":"https://jsonfeed.org/version/1.1"}