A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-0496 A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
Github GHSA Github GHSA GHSA-3ww4-gg4f-jr7f Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
Ubuntu USN Ubuntu USN USN-6673-1 python-cryptography vulnerabilities
Ubuntu USN Ubuntu USN USN-6673-2 python-cryptography vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00707}

epss

{'score': 0.00726}


Tue, 17 Jun 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 22 Nov 2024 12:00:00 +0000

Type Values Removed Values Added
References

Fri, 27 Sep 2024 19:45:00 +0000

Type Values Removed Values Added
References

Thu, 05 Sep 2024 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Couchbase
Couchbase couchbase Server
Cryptography.io
Cryptography.io cryptography
CPEs cpe:2.3:a:python-cryptography_project:python-cryptography:*:*:*:*:*:*:*:* cpe:2.3:a:couchbase:couchbase_server:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:couchbase:couchbase_server:7.6.1:*:*:*:*:*:*:*
cpe:2.3:a:cryptography.io:cryptography:*:*:*:*:*:python:*:*
Vendors & Products Python-cryptography Project
Python-cryptography Project python-cryptography
Couchbase
Couchbase couchbase Server
Cryptography.io
Cryptography.io cryptography

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-09-12T20:02:35.058Z

Reserved: 2023-12-13T20:44:02.023Z

Link: CVE-2023-50782

cve-icon Vulnrichment

Updated: 2024-08-02T22:23:43.327Z

cve-icon NVD

Status : Modified

Published: 2024-02-05T21:15:11.183

Modified: 2024-11-21T08:37:18.337

Link: CVE-2023-50782

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-12-13T00:00:00Z

Links: CVE-2023-50782 - Bugzilla

cve-icon OpenCVE Enrichment

No data.