{"id":"CVE-2026-44368","aliases":["GHSA-7r92-3jgr-r65q","PYSEC-2026-3028"],"url":"https://o3.security/vulnerability/CVE-2026-44368","summary":"PyQuorum: Timing side‑channel in mul_mod","details":"PyQuorum is a cryptographic library for secret sharing and key management. Prior to 0.2.1, the mul_mod function implements multiplication via a binary expansion loop whose execution time depends on the Hamming weight of the second operand (the exponent). An attacker who can measure the time of secret‑sharing operations (e.g., via a remote service) could progressively recover the values of shares, ultimately leading to secret reconstruction. This vulnerability is fixed in 0.2.1.","published":"2026-05-13T20:18:12.910Z","modified":"2026-08-07T11:31:15.934377204Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"pyquorum","fixedVersion":"0.2.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44368.json"},{"type":"ADVISORY","url":"https://github.com/svvqt/pyquorum/security/advisories/GHSA-7r92-3jgr-r65q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44368"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:15.934377204Z"}}