CVE-2020-25659
published 2021-01-11CVE-2020-25659: python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.
PriorityP431medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
2.45%
82.6th percentile
python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cryptography.io | cryptography | — | — |
| cryptography.io | cryptography | >= 0 < 3.2 | 3.2 |
| debian | python-cryptography | < python-cryptography 3.2.1-1 (bookworm) | python-cryptography 3.2.1-1 (bookworm) |
| msrc | azl3_python-cryptography_3.3.2-5_on_azure_linux_3.0 | — | — |
| msrc | azl3_python-cryptography_42.0.5-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_python-cryptography_3.3.2-7_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_python-cryptography_2.3.1-4_on_cbl_mariner_1.0 | — | — |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_msrc7.5HIGH
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659
vendor_msrc·2024-02-13·CVSS 7.5
CVE-2023-50782 [HIGH] CWE-203 Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659
Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Ye
Red Hat
python-cryptography: Bleichenbacher timing oracle attack against RSA decryption - incomplete fix for CVE-2020-25659
vendor_redhat·2023-12-13·CVSS 5.9
CVE-2023-50782 [MEDIUM] CWE-203 python-cryptography: Bleichenbacher timing oracle attack against RSA decryption - incomplete fix for CVE-2020-25659
python-cryptography: Bleichenbacher timing oracle attack against RSA decryption - incomplete fix for CVE-2020-25659
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
Statement: This vulnerability exists due to an incomplete fix for CVE-2020-25659.
The CVE-2020-25659 vulnerability presents a moderate severity concern due to its specific impact on applications utilizing RSA decryption with PKCS
Microsoft
python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API via timed processing of valid PKCS#1 v1.5 ciphertext.
vendor_msrc·2021-01-12·CVSS 5.9
CVE-2020-25659 [MEDIUM] CWE-385 python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API via timed processing of valid PKCS#1 v1.5 ciphertext.
python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API via timed processing of valid PKCS#1 v1.5 ciphertext.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: r
Ubuntu
python-cryptography vulnerability
vendor_ubuntu·2020-11-03
CVE-2020-25659 python-cryptography vulnerability
Title: python-cryptography vulnerability
Summary: python-cryptography could be made to expose sensitive information over the
network.
Hubert Kario discovered that python-cryptography incorrectly handled certain decryption.
An attacker could possibly use this issue to expose sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python-cryptography: Bleichenbacher timing oracle attack against RSA decryption
vendor_redhat·2020-10-25·CVSS 5.9
CVE-2020-25659 [MEDIUM] CWE-385 python-cryptography: Bleichenbacher timing oracle attack against RSA decryption
python-cryptography: Bleichenbacher timing oracle attack against RSA decryption
python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.
A flaw was found in python-cryptography, where it is vulnerable to Bleichenbacher timing attacks. This flaw allows an attacker, via the RSA decryption API, to decrypt parts of the ciphertext encrypted with RSA. The highest threat from this vulnerability is to confidentiality.
Statement: In Red Hat OpenStack Platform, because the flaw has a lower impact and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP python-cryptography package.
Package: python-cryptography (CloudForms Management Engine 5) -
Debian
CVE-2020-25659: python-cryptography - python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RS...
vendor_debian·2020·CVSS 5.9
CVE-2020-25659 [MEDIUM] CVE-2020-25659: python-cryptography - python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RS...
python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.
Scope: local
bookworm: resolved (fixed in 3.2.1-1)
bullseye: resolved (fixed in 3.2.1-1)
forky: resolved (fixed in 3.2.1-1)
sid: resolved (fixed in 3.2.1-1)
trixie: resolved (fixed in 3.2.1-1)
OSV
CVE-2020-25659: python-cryptography 3
osv·2021-01-11·CVSS 5.9
CVE-2020-25659 [MEDIUM] CVE-2020-25659: python-cryptography 3
python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.
GHSA
RSA decryption vulnerable to Bleichenbacher timing vulnerability
ghsa·2020-10-27
CVE-2020-25659 [HIGH] CWE-385 RSA decryption vulnerable to Bleichenbacher timing vulnerability
RSA decryption vulnerable to Bleichenbacher timing vulnerability
RSA decryption was vulnerable to Bleichenbacher timing vulnerabilities, which would impact people using RSA decryption in online scenarios. This is fixed in cryptography 3.2.
OSV
RSA decryption vulnerable to Bleichenbacher timing vulnerability
osv·2020-10-27
CVE-2020-25659 [HIGH] RSA decryption vulnerable to Bleichenbacher timing vulnerability
RSA decryption vulnerable to Bleichenbacher timing vulnerability
RSA decryption was vulnerable to Bleichenbacher timing vulnerabilities, which would impact people using RSA decryption in online scenarios. This is fixed in cryptography 3.2.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-50782 python-cryptography: Bleichenbacher timing oracle attack against RSA decryption - incomplete fix for CVE-2020-25659
bugzilla·2023-12-13·CVSS 5.9
CVE-2023-50782 [MEDIUM] CVE-2023-50782 python-cryptography: Bleichenbacher timing oracle attack against RSA decryption - incomplete fix for CVE-2020-25659
CVE-2023-50782 python-cryptography: Bleichenbacher timing oracle attack against RSA decryption - incomplete fix for CVE-2020-25659
Description:
The fix for CVE-2020-25659 is not addressing the leakage in the RSA
decryption. Because of the API design, the fix is generally not
believed to be possible to be fully addressed. The issue can be
mitigated by using a cryptographic backed that implements implicit
rejection (Marvin workaround). Only applications that use RSA decryption
with PKCS#1 v1.5 padding are affected.
Implicit rejection in RHEL has shipped in 9.3.0. Will ship in 9.2.eus,
8.6.eus, 8.8.eus, and 8.9.z. No other releases are planned
References:
https://github.com/pyca/cryptography/issues/9785
https://people.redhat.com/~hkario/marvin/
https://github.com/openssl/openssl/pull/13817
Bugzilla
CVE-2020-25659 python-cryptography: Bleichenbacher timing oracle attack against RSA decryption
bugzilla·2020-10-21·CVSS 5.9
CVE-2020-25659 [MEDIUM] CVE-2020-25659 python-cryptography: Bleichenbacher timing oracle attack against RSA decryption
CVE-2020-25659 python-cryptography: Bleichenbacher timing oracle attack against RSA decryption
python-cryptography is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.
Discussion:
Upstream commit: https://github.com/pyca/cryptography/pull/5507/commits/ce1bef6f1ee06ac497ca0c837fbd1c7ef6c2472b
---
Acknowledgments:
Name: Hubert Kario (Red Hat)
---
The upstream patch in python-cryptography >= 3.2 is only a partial mitigation against Bleichenbacher attacks.
Quote from upstream changelog:
**SECURITY ISSUE:** Attempted to make RSA PKCS#1v1.5 decryption more constant
time, to protect against Bleichenbacher vulnerabilities. Due to limitations
imposed by our API, we cannot completely mitigate this vulnerability and
Bleepingcomputer
New Marvin attack revives 25-year-old decryption flaw in RSA
blogs_bleepingcomputer·2023-10-01·CVSS 5.9
[MEDIUM] New Marvin attack revives 25-year-old decryption flaw in RSA
## New Marvin attack revives 25-year-old decryption flaw in RSA
## Bill Toulas
A flaw related to the PKCS #1 v1.5 padding in SSL servers discovered in 1998 and believed to have been resolved still impacts several widely-used projects today.
After extensive testing that measures end-to-end operations, Red Hat researchers discovered several variations of the original timing attack, collectively called the 'Marvin Attack,' which can effectively bypass fixes and mitigations.
The problem allows attackers to potentially decrypt RSA ciphertexts, forge signatures, and even decrypt sessions recorded on a vulnerable TLS server.
Using standard hardware, the researchers demonstrated that executing the Marvin Attack within just a couple of hours is possible, proving its practicality.
Red Hat warn
https://github.com/pyca/cryptography/pull/5507/commits/ce1bef6f1ee06ac497ca0c837fbd1c7ef6c2472bhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://github.com/pyca/cryptography/pull/5507/commits/ce1bef6f1ee06ac497ca0c837fbd1c7ef6c2472bhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.html
2021-01-11
Published