CVE-2020-25658
It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.23%
- CWE
- CWE-385
- Published
- 2020-11-12
- Last modified
- 2026-03-14
Affected products
- Sybren A. Stüvel python-rsa
Weakness type
Related vulnerabilities
- CVE-2025-53826 — FileBrowser Has Insecure JWT Handling Which Allows Session Replay Attacks after Logout
- CVE-2024-0553 — Gnutls: incomplete fix for cve-2023-5981
- CVE-2023-50782 — Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659
- CVE-2025-59425 — vLLM vulnerable to timing attack at bearer auth
- CVE-2026-5598 — Non-constant time comparisons risk private key leakage in FrodoKEM.
- CVE-2024-23342 — python-ecdsa vulnerable to Minerva attack on P-256
- CVE-2025-9231 — Timing side-channel in SM2 algorithm on 64 bit ARM
- CVE-2020-29506 — Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, con