{"schema_version":"1.7.5","id":"CVE-2020-25659","published":"2021-01-11T16:15:15.040Z","modified":"2026-08-07T10:12:03.897016357Z","aliases":["GHSA-hggm-jpg3-v476","PYSEC-2021-62"],"related":["SUSE-FU-2022:0444-1","SUSE-FU-2022:0445-1","SUSE-RU-2021:0985-1","SUSE-RU-2022:2355-1","SUSE-SU-2020:3592-1","SUSE-SU-2020:3629-1","SUSE-SU-2023:0604-1","SUSE-SU-2023:2783-1","SUSE-SU-2023:2783-2","openSUSE-SU-2020:2173-1","openSUSE-SU-2024:11223-1","openSUSE-SU-2024:13819-1","openSUSE-SU-2026:11468-1"],"details":"python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pyca/cryptography","events":[{"introduced":"c9e65222c91df8b6f61650a3460e30232962c1e0"},{"last_affected":"c9e65222c91df8b6f61650a3460e30232962c1e0"}],"database_specific":{"cpe":"cpe:2.3:a:cryptography.io:cryptography:3.2:*:*:*:*:python:*:*","extracted_events":[{"introduced":"3.2"},{"last_affected":"3.2"}],"source":"CPE_STRING"}}],"versions":["3.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-25659.json"}}],"references":[{"type":"FIX","url":"https://github.com/pyca/cryptography/pull/5507/commits/ce1bef6f1ee06ac497ca0c837fbd1c7ef6c2472b"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuapr2022.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujul2022.html"}],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:1.10.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.10.0"},{"last_affected":"1.10.0"}],"source":"CPE_STRING","vendor_product":"oracle:communications_cloud_native_core_network_function_cloud_native_environment"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}