CVE-2026-69247

Aliases:GHSA-g6cj-pr64-35w5PYSEC-2026-3552UBUNTU-CVE-2026-69247DEBIAN-CVE-2026-69247CGA-26q5-j34f-gp9qCGA-2g3j-v4vm-r826CGA-34qh-r794-3mc9CGA-3cp7-66hw-c3p2CGA-3vgj-293m-h9mhCGA-56x5-v796-6jv2CGA-59px-gmmj-r32qCGA-6h5p-4vxw-r89gCGA-6whw-6wwq-84xqCGA-87mg-jmrr-9rvvCGA-8g7w-hqvx-cqwcCGA-8pvm-rc42-7wvfCGA-96xg-j54g-9gmqCGA-9chr-683h-45j8CGA-9wwh-vv6g-wcv4CGA-c32g-g77q-8hhgCGA-cfrh-w7hj-m7r9CGA-fmcj-mc5j-998hCGA-fr3r-8j84-8xcpCGA-ghhr-628c-w794CGA-hgpf-8mv8-gp92CGA-hpx6-cw28-88hwCGA-hvpj-cmf7-c27wCGA-jfc9-2hmp-87hjCGA-jh36-gq9h-59q5CGA-jj9f-q722-5j8vCGA-jm42-q4xx-g9w3CGA-jq6r-5hjr-ggmrCGA-p2gc-p98w-vpv5CGA-225w-mvmm-hw3qCGA-227q-jj3g-g453CGA-24vw-gch2-pcjrCGA-2crr-3vrc-wp54CGA-2f78-qvhp-cg2hCGA-2j5x-2qrv-3rwqCGA-2qjq-xj2w-h6wcCGA-2r8c-2f5w-987fCGA-3295-cpf3-3qj9CGA-35h8-rvhr-5hq8CGA-372q-wxx7-23vrCGA-3957-gcp2-h2g5CGA-3c59-5xpq-2x27CGA-3f63-w84q-c6cwCGA-3h75-fq9v-c2w7CGA-3hf6-v63q-mch9CGA-3r5g-j469-66g2CGA-3r64-wc43-vh8gCGA-3xgp-vf93-hccmCGA-4fm2-6xrf-p3vqCGA-4xm6-xphq-33rhCGA-539v-7r6j-cxfcCGA-55jh-fm85-9jvjCGA-562q-29ff-w485CGA-567r-mmwj-j352CGA-57h3-mg84-v85gCGA-5c7w-fg4x-48m6CGA-5qp9-pj6v-gwxwCGA-5vj9-w59r-7rqjCGA-5vwm-73p7-jcjpCGA-635h-p3hq-6945CGA-68fh-g688-rpqxCGA-6934-73h4-r53qCGA-6ffv-78x3-p2hxCGA-6fgc-h56j-w9frCGA-6jpr-8fxx-8rw5CGA-6xvx-53r8-qpmpCGA-7494-6hpp-fg2hCGA-74ff-46h4-9mxhCGA-77hv-x7fj-w36rCGA-7c85-2rv2-vcc4CGA-7j6q-q355-h769CGA-7mpm-q4xm-r2mcCGA-7pvv-772q-wgvfCGA-7qvj-vvrp-85h4CGA-825q-f83q-qq22CGA-8386-hprr-pp8vCGA-83m3-3x2v-q337CGA-87r5-j95p-3x95CGA-87xr-f72p-343xCGA-89g3-5cpq-mcr3CGA-944x-wh7h-f72fCGA-954q-h7gm-84f6CGA-95fp-gc5w-ph63CGA-95g3-gm83-c6xfCGA-9cv9-wmh8-7fg6CGA-9h2p-jwgw-gg2pCGA-9hfc-78gg-2rqpCGA-9hjf-ccq7-vfrvCGA-9jmq-hwg9-vf9rCGA-9mhg-h576-w384CGA-c2vc-7r77-rfw7CGA-c3g5-j4mq-6g7mCGA-cf96-869x-f53cCGA-cfv5-9p77-893hCGA-cgcm-26vq-q29xCGA-ch5g-8559-ww8rCGA-cjg4-h7h3-gr9cCGA-cw6x-77r7-pvxwCGA-f2mm-5q33-grqcCGA-f2x2-f546-j73wCGA-f3qj-x3rj-fpfvCGA-f5rq-f45w-ph35CGA-f5xx-44xw-46wgCGA-f69j-8r5w-2cj8CGA-f854-2jvq-394pCGA-fgjv-3fx7-m7qmCGA-fv4q-cc9p-cf29CGA-fwg6-5r79-mfvfCGA-fwx8-jmhp-jcvvCGA-g744-92gc-rh7hCGA-g9jc-fxh6-2fhmCGA-gvvf-84xh-h795CGA-h4gx-3vmm-2x6jCGA-h7v3-6gwc-mx9jCGA-h9mh-385m-p488CGA-hhr5-gvxw-fj62CGA-hpw3-hwhr-4cq6CGA-hv27-hx49-wmp6CGA-hw9q-3xrq-8pv8CGA-hxjf-cwrw-jjh3CGA-hxrp-cwmj-mjpqCGA-j3mr-75p5-332fCGA-j3v8-8mwq-wvgmCGA-j7jg-hp54-x8cpCGA-j995-88hr-p66fCGA-j9gh-c6v3-224rCGA-jgq6-43jj-fqfhCGA-jm8r-42xp-g4hxCGA-jr7h-fprw-w38vCGA-jr7j-f3vg-x7fxCGA-m2w6-8gp4-xrjwCGA-m5qm-m397-q735CGA-m5rj-3q6x-j3fwCGA-mjv8-4c86-8rx5CGA-mmgf-938x-wqmmCGA-p5jr-jr35-mj49CGA-p5rq-q8hr-5xq7CGA-p962-4q54-66x3CGA-pcfp-wxwq-fg48CGA-pcmg-p5r5-h6rmCGA-pg39-3f49-vrxgCGA-ppgh-7ff3-jpcjCGA-prvh-m6j8-x2x2CGA-pw2p-3xw8-r323CGA-q4gq-ch54-8qv7CGA-q4r4-mxp9-9562CGA-q8g4-9fr9-46p9CGA-q9j3-5w89-3r39CGA-qch4-8m3x-h27cCGA-qm2r-r9vj-53x5CGA-qmjj-jx6h-9967CGA-qpj8-p5c3-pj7fCGA-qq8p-prm5-g7xvCGA-qr5v-52g2-3r83CGA-qrhv-48f3-6cq6CGA-qvc5-f78w-xxcqCGA-r2ch-m4qj-gxv4CGA-r2w9-rppj-88wrCGA-r4q7-cg5x-2g5pCGA-r52h-25mp-5x6wCGA-r765-2h32-pmwcCGA-r9q9-mcvq-vhhvCGA-rjf6-p7v5-5wx7CGA-rmfp-4vc5-wwgmCGA-rq57-5jcp-hc35CGA-rrhc-qg66-qm65CGA-rrm7-pjxg-3xcvCGA-rwhv-qr8h-5x5xCGA-rxj7-37g7-fc9pCGA-rxw7-mx2f-6g35CGA-v3mf-m8gc-p79vCGA-v8c6-92g3-xr8xCGA-vc5v-g6r3-q5xhCGA-vcmf-fh5x-qphfCGA-vh4q-vvw2-vc3jCGA-vh7g-7gx2-r3fqCGA-vhg9-qm82-wwfxCGA-vjvh-gg7c-49vvCGA-vp36-fqw2-wrc3CGA-w2hp-xghx-g92gCGA-w5wq-9v56-r8f6CGA-w672-v9pw-83f7CGA-w733-2rrj-rwxcCGA-w9p9-chwf-3q3xCGA-wc79-76wj-7p97CGA-wc9h-jm2q-642cCGA-wgv4-rj8g-rvrfCGA-whvf-fjj6-mfxvCGA-wmg9-mv52-rxjmCGA-wpjq-xf3h-449pCGA-wr6h-q9qh-mf26CGA-wwfw-x4cg-x97wCGA-x36f-82pg-r98fCGA-x892-cw4m-4jr6CGA-x8x5-6m6x-fv63CGA-xhm8-4fcv-rj9fCGA-hxgx-2q7x-mg6mCGA-vg38-f894-93wgCGA-4x38-r2h9-9mhhCGA-5453-mm96-69rqCGA-7gj7-hc7w-m78cCGA-99r6-68pg-22fqCGA-hwhx-6hh7-8rgjCGA-jhr2-986m-8xxgCGA-mfv6-485x-vwmvCGA-qcr8-xfv8-x9vqCGA-w8jp-28c6-wghvCGA-x5x6-jhpp-74pjCGA-4pjr-fqm3-28mjCGA-4fmw-287q-93gcCGA-288p-pwmq-w37fCGA-2xvc-q2pj-h6hq
Awaiting Analysis
Published: 03 Aug 2026, 21:16
Last modified:04 Aug 2026, 14:09

Vulnerability Summary

Overall Risk (default)
medium
33/100
CVSS Score
8.2 HIGH
v4.0 (cve.org)
EPSS Score
0.18% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

03 Aug 2026, 21:16
Published
Vulnerability first disclosed
04 Aug 2026, 14:09
Last Modified
Vulnerability information updated

Description

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the exact length recovered from the RSA operation. The same distinction was also observable by timing. An application that decrypts attacker-supplied EnvelopedData and reflects the outcome gives the attacker a Bleichenbacher oracle against the content-encryption key. Decryption ran as RSA PKCS#1 v1.5 decrypt of encryptedKey, build an AES cipher from the result, then AES-CBC decrypt and PKCS#7 unpad. Invalid RSA padding, a valid padding with a bad key length, a correct length with a wrong key, and the real key each failed or succeeded differently. Case 1 is reachable only where the linked library lacks implicit rejection: OpenSSL 3.0 and 3.1, LibreSSL, and BoringSSL. Exploitation requires a service that auto-decrypts untrusted EnvelopedData matching the victim certificate and answers adaptively at high volume, such as an S/MIME gateway or mail filter. This issue is fixed in 50.0.0.

CVSS Metrics

  • v4.0HIGHScore: 8.2CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
  • v4.0HIGHScore: 8.2CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS Trends

Current EPSS score: 0.18% Percentile: 7%

Techniques & Countermeasures

  • CWE-208Observable Timing Discrepancy

    Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.

  • CWE-209Generation of Error Message Containing Sensitive Information

    The product generates an error message that includes sensitive information about its environment, users, or associated data.

Affected Systems

  • chainguardairflow-2

    all

  • chainguardairflow-3

    < 3.3.0-r4

  • chainguardairflow-3-iamguarded-compat

    all

  • chainguardairflow-core-2

    all

  • chainguardairflow-core-3

    < 3.3.0-r5

  • chainguardansible-operator

    < 1.42.3-r8 | < 1.42.3-r9

  • chainguardansible-operator-fips

    < 1.42.3-r5

  • chainguardapache-beam-python-3.11-sdk

    < 2.75.0-r3

  • chainguardapache-beam-python-3.12-sdk

    < 2.75.0-r2

  • chainguardapache-beam-python-3.13-sdk

    < 2.75.0-r4

  • chainguardapache-beam-python-3.14-sdk

    < 2.75.0-r2

  • chainguardauthentik-2025.12

    all

  • chainguardauthentik-2026.2

    < 2026.2.6-r15

  • chainguardauthentik-2026.5

    < 2026.5.6-r8

  • chainguardawx

    < 24.6.1-r49

  • chainguardaz

    all

  • chainguardazureml-inference-server-http

    < 1.5.1-r8

  • chainguardbarman

    < 3.19.1-r5

  • chainguardbarman-cloudnative-pg

    < 3.19.1-r5

  • chainguardcrossplane-function-pythonic

    < 0.6.1-r2

  • chainguarddagster

    < 1.13.16-r1

  • chainguarddask-kubernetes

    < 2026.3.0-r11

  • chainguarddask-kubernetes-fips

    < 2026.3.0-r7

  • chainguarddatadog-agent-7.71-core-integrations

    all

  • chainguarddatadog-agent-7.72-core-integrations

    all

  • chainguarddatadog-agent-7.73-core-integrations

    all

  • chainguarddatadog-agent-7.74-core-integrations

    all

  • chainguarddatadog-agent-7.75-core-integrations

    all

  • chainguarddatadog-agent-7.76-core-integrations

    all

  • chainguarddatadog-agent-7.77-core-integrations

    all

  • chainguarddatadog-agent-7.78-core-integrations

    all

  • chainguarddatadog-agent-7.79-core-integrations

    all

  • chainguarddatadog-agent-7.80-core-integrations

    < 7.80.4-r10

  • chainguarddatadog-agent-fips-7.71-core-integrations

    all

  • chainguarddatadog-agent-fips-7.72-core-integrations

    all

  • chainguarddatadog-agent-fips-7.73-core-integrations

    all

  • chainguarddatadog-agent-fips-7.74-core-integrations

    all

  • chainguarddatadog-agent-fips-7.75-core-integrations

    all

  • chainguarddatadog-agent-fips-7.76-core-integrations

    all

  • chainguarddatadog-agent-fips-7.77-core-integrations

    all

  • chainguarddatadog-agent-fips-7.78-core-integrations

    all

  • chainguarddatadog-agent-fips-7.79-core-integrations

    all

  • chainguarddatadog-agent-fips-7.80-core-integrations

    < 7.80.4-r10

  • chainguarddatadog-agent-fips-7.81-core-integrations

    < 7.81.3-r1

  • chainguarddbt-bigquery

    < 1.10.3-r7

  • chainguarddbt-snowflake

    all

  • chainguardduplicity

    < 3.1.0-r2

  • chainguardggshield

    < 1.53.0-r1

  • chainguardgitlab-toolbox-ce-19.2

    < 19.2.1-r1

  • chainguardgitlab-toolbox-ce-fips-18.11

    all

Showing first 50 affected entries in server-rendered view.

References (12)