OPENSUSE-SU-2026:21685-1
Advisory lineage Upstream: 3 Downstream: 0
Published: 30 Aug 2026, 14:35
Last modified:31 Aug 2026, 18:15
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
30 Aug 2026, 14:35
Published
Vulnerability first disclosed
31 Aug 2026, 18:15
Last Modified
Vulnerability information updated
Description
Security update for python-cryptography This update for python-cryptography fixes the following issues: - CVE-2026-69247: PKCS#7 `EnvelopedData` decryption exposes a Bleichenbacher oracle through distinguishable errors and timing (bsc#1273551). - CVE-2026-69248: verifier accepts wildcard DNS names allowing escape from `permittedSubtrees` (bsc#1273549). - CVE-2026-69249: duplicate self-signed intermediates can cause exponential path-building (bsc#1273516).
Affected Systems
- opensuse•python-cryptography&distro=openSUSE Leap 16.0
< 44.0.3-160000.5.1