{"document":{"aggregate_severity":{"namespace":"https://access.redhat.com/security/updates/classification/","text":"Moderate"},"category":"csaf_vex","csaf_version":"2.0","distribution":{"text":"Copyright © Red Hat, Inc. All rights reserved.","tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en","notes":[{"category":"legal_disclaimer","text":"This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.","title":"Terms of Use"}],"publisher":{"category":"vendor","contact_details":"https://access.redhat.com/security/team/contact/","issuing_authority":"Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.","name":"Red Hat Product Security","namespace":"https://www.redhat.com"},"references":[{"category":"self","summary":"Canonical URL","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-69247.json"}],"title":"python-cryptography: python-cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing","tracking":{"current_release_date":"2026-08-28T21:20:23+00:00","generator":{"date":"2026-08-28T21:20:23+00:00","engine":{"name":"Red Hat SDEngine","version":"5.3.16"}},"id":"CVE-2026-69247","initial_release_date":"2026-08-03T21:16:32.047000+00:00","revision_history":[{"date":"2026-08-03T21:16:32.047000+00:00","number":"1","summary":"Initial version"},{"date":"2026-08-28T21:11:52+00:00","number":"2","summary":"Current version"},{"date":"2026-08-28T21:20:23+00:00","number":"3","summary":"Last generated version"}],"status":"final","version":"3"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"Red Hat Enterprise Linux 10","product":{"name":"Red Hat Enterprise Linux 10","product_id":"red_hat_enterprise_linux_10","product_identification_helper":{"cpe":"cpe:/o:redhat:enterprise_linux:10"}}}],"category":"product_family","name":"Red Hat Enterprise Linux 10"},{"branches":[{"category":"product_name","name":"Red Hat Enterprise Linux 9","product":{"name":"Red Hat Enterprise Linux 9","product_id":"red_hat_enterprise_linux_9","product_identification_helper":{"cpe":"cpe:/o:redhat:enterprise_linux:9"}}}],"category":"product_family","name":"Red Hat Enterprise Linux 9"},{"category":"product_version","name":"python3.14-cryptography.src","product":{"name":"python3.14-cryptography.src","product_id":"python3.14-cryptography.src","product_identification_helper":{"purl":"pkg:rpm/redhat/python3.14-cryptography@45.0.4-4.el10?arch=src"}}},{"category":"product_version","name":"python3-cryptography","product":{"name":"python3-cryptography","product_id":"python3-cryptography","product_identification_helper":{"purl":"pkg:rpm/redhat/python3-cryptography"}}},{"category":"product_version","name":"rhel10/keylime-registrar","product":{"name":"rhel10/keylime-registrar","product_id":"rhel10/keylime-registrar","product_identification_helper":{"purl":"pkg:oci/keylime-registrar?repository_url=registry.redhat.io/rhel10/keylime-registrar"}}},{"category":"product_version","name":"rhel10/keylime-verifier","product":{"name":"rhel10/keylime-verifier","product_id":"rhel10/keylime-verifier","product_identification_helper":{"purl":"pkg:oci/keylime-verifier?repository_url=registry.redhat.io/rhel10/keylime-verifier"}}}],"category":"vendor","name":"Red Hat"}],"relationships":[{"category":"default_component_of","full_product_name":{"name":"python3-cryptography as a component of Red Hat Enterprise Linux 10","product_id":"red_hat_enterprise_linux_10:python3-cryptography"},"product_reference":"python3-cryptography","relates_to_product_reference":"red_hat_enterprise_linux_10"},{"category":"default_component_of","full_product_name":{"name":"python3.14-cryptography.src as a component of Red Hat Enterprise Linux 10","product_id":"red_hat_enterprise_linux_10:python3.14-cryptography.src"},"product_reference":"python3.14-cryptography.src","relates_to_product_reference":"red_hat_enterprise_linux_10"},{"category":"default_component_of","full_product_name":{"name":"rhel10/keylime-registrar as a component of Red Hat Enterprise Linux 10","product_id":"red_hat_enterprise_linux_10:rhel10/keylime-registrar"},"product_reference":"rhel10/keylime-registrar","relates_to_product_reference":"red_hat_enterprise_linux_10"},{"category":"default_component_of","full_product_name":{"name":"rhel10/keylime-verifier as a component of Red Hat Enterprise Linux 10","product_id":"red_hat_enterprise_linux_10:rhel10/keylime-verifier"},"product_reference":"rhel10/keylime-verifier","relates_to_product_reference":"red_hat_enterprise_linux_10"},{"category":"default_component_of","full_product_name":{"name":"python3.14-cryptography.src as a component of Red Hat Enterprise Linux 9","product_id":"red_hat_enterprise_linux_9:python3.14-cryptography.src"},"product_reference":"python3.14-cryptography.src","relates_to_product_reference":"red_hat_enterprise_linux_9"}]},"vulnerabilities":[{"cve":"CVE-2026-69247","cwe":{"id":"CWE-208","name":"Observable Timing Discrepancy"},"discovery_date":"2026-08-03T22:03:10.728292+00:00","flags":[{"label":"vulnerable_code_not_present","product_ids":["red_hat_enterprise_linux_10:rhel10/keylime-registrar","red_hat_enterprise_linux_10:rhel10/keylime-verifier"]}],"ids":[{"system_name":"Red Hat Bugzilla ID","text":"2510835"}],"notes":[{"category":"description","text":"A flaw was found in cryptography, a Python package for cryptographic primitives. This vulnerability, known as a Bleichenbacher oracle, arises during PKCS#7 EnvelopedData decryption. An attacker can exploit distinguishable error messages and timing differences during decryption to gain information about the content-encryption key. Exploitation requires a high-volume service, such as an S/MIME gateway, that automatically decrypts untrusted data matching a victim's certificate. Successful exploitation could lead to the disclosure of sensitive encryption keys, allowing an attacker to decrypt confidential communications.","title":"Vulnerability description"},{"category":"summary","text":"python-cryptography: python-cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing","title":"Vulnerability summary"},{"category":"other","text":"Red Hat rates this Moderate (CVSS 3.1 5.9). Exploitation requires an application that decrypts attacker-supplied PKCS#7 EnvelopedData via pkcs7_decrypt_* and leaks errors or timing. GitHub CNA CVSS 4.0 8.2 assumes that oracle is readily available.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"known_affected":["red_hat_enterprise_linux_10:python3-cryptography","red_hat_enterprise_linux_10:python3.14-cryptography.src","red_hat_enterprise_linux_9:python3.14-cryptography.src"],"known_not_affected":["red_hat_enterprise_linux_10:rhel10/keylime-registrar","red_hat_enterprise_linux_10:rhel10/keylime-verifier"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-69247"},{"category":"external","summary":"RHBZ#2510835","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2510835"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-69247","url":"https://www.cve.org/CVERecord?id=CVE-2026-69247"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-69247","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69247"},{"category":"external","summary":"https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f","url":"https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f"},{"category":"external","summary":"https://github.com/pyca/cryptography/pull/15369","url":"https://github.com/pyca/cryptography/pull/15369"},{"category":"external","summary":"https://github.com/pyca/cryptography/security/advisories/GHSA-g6cj-pr64-35w5","url":"https://github.com/pyca/cryptography/security/advisories/GHSA-g6cj-pr64-35w5"}],"release_date":"2026-08-03T21:16:32.047000+00:00","remediations":[{"category":"workaround","details":"The vulnerable APIs were introduced in cryptography 44.0.0 and fixed in 50.0.0.","product_ids":["red_hat_enterprise_linux_10:python3-cryptography","red_hat_enterprise_linux_10:python3.14-cryptography.src","red_hat_enterprise_linux_9:python3.14-cryptography.src"]},{"category":"none_available","details":"Fix deferred","product_ids":["red_hat_enterprise_linux_10:python3-cryptography","red_hat_enterprise_linux_10:python3.14-cryptography.src","red_hat_enterprise_linux_9:python3.14-cryptography.src"]}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["red_hat_enterprise_linux_10:python3-cryptography","red_hat_enterprise_linux_10:python3.14-cryptography.src","red_hat_enterprise_linux_10:rhel10/keylime-registrar","red_hat_enterprise_linux_10:rhel10/keylime-verifier","red_hat_enterprise_linux_9:python3.14-cryptography.src"]}],"threats":[{"category":"impact","details":"Moderate","product_ids":["red_hat_enterprise_linux_10:python3-cryptography","red_hat_enterprise_linux_10:python3.14-cryptography.src","red_hat_enterprise_linux_10:rhel10/keylime-registrar","red_hat_enterprise_linux_10:rhel10/keylime-verifier","red_hat_enterprise_linux_9:python3.14-cryptography.src"]}],"title":"python-cryptography: python-cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing"}]}