{"id":"CVE-2020-25659","aliases":["GHSA-hggm-jpg3-v476","PYSEC-2021-62"],"url":"https://o3.security/vulnerability/CVE-2020-25659","summary":"RSA decryption vulnerable to Bleichenbacher timing vulnerability","details":"python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.","published":"2021-01-11T16:15:15.040Z","modified":"2026-08-07T10:12:03.897016357Z","cvss":{"score":5.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"cryptography","fixedVersion":"3.2"}],"fix":{"url":"https://github.com/pyca/cryptography/pull/5507/commits/ce1bef6f1ee06ac497ca0c837fbd1c7ef6c2472b","label":"pyca/cryptography#5507"},"references":[{"type":"FIX","url":"https://github.com/pyca/cryptography/pull/5507/commits/ce1bef6f1ee06ac497ca0c837fbd1c7ef6c2472b"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuapr2022.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujul2022.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T10:12:03.897016357Z"}}