{"id":"CVE-2026-44368","aliases":["GHSA-7r92-3jgr-r65q","PYSEC-2026-3028"],"url":"https://o3.security/vulnerability/CVE-2026-44368","summary":"PyQuorum: Timing side‑channel in mul_mod","details":"PyQuorum is a cryptographic library for secret sharing and key management. Prior to 0.2.1, the mul_mod function implements multiplication via a binary expansion loop whose execution time depends on the Hamming weight of the second operand (the exponent). An attacker who can measure the time of secret‑sharing operations (e.g., via a remote service) could progressively recover the values of shares, ultimately leading to secret reconstruction. This vulnerability is fixed in 0.2.1.","published":"2026-05-13T20:18:12.910Z","modified":"2026-08-12T03:51:13.727904642Z","cvss":null,"epss":{"score":0.00314,"percentile":0.24374,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"pyquorum","fixedVersion":"0.2.1"}],"fix":{"url":"https://github.com/svvqt/pyquorum/commit/1e9ac41dd3c305c13d7a6b7d227bf325be82d730","label":"svvqt/pyquorum@1e9ac41"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44368.json"},{"type":"ADVISORY","url":"https://github.com/svvqt/pyquorum/security/advisories/GHSA-7r92-3jgr-r65q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44368"},{"type":"WEB","url":"https://github.com/svvqt/pyquorum/commit/1e9ac41dd3c305c13d7a6b7d227bf325be82d730"},{"type":"PACKAGE","url":"https://github.com/svvqt/pyquorum"},{"type":"WEB","url":"https://github.com/svvqt/pyquorum/releases/tag/v0.2.1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:13.727904642Z"}}