A high-severity flaw tracked as CVE-2026-69247 was disclosed in the Python cryptography package, where PKCS#7 EnvelopedData decryption can leak distinguishable errors and timing differences during RSA PKCS#1 v1.5 processing. The bug affects versions 44.0.0 through 49.x and enables a classic Bleichenbacher-style oracle against RecipientInfo encryptedKey handling, potentially allowing an unauthenticated remote attacker to recover content-encryption keys and decrypt sensitive PKCS#7-protected data such as S/MIME messages.
The exposure is most relevant to services that decrypt attacker-supplied PKCS#7 content at scale, including S/MIME gateways, secure mail filters, and document-processing systems. Reports say the issue stems from non-uniform error handling, early aborts, and observable timing discrepancies across invalid padding, wrong key sizes, malformed keys, and successful decryptions; cryptography 50.0.0 fixes the problem by using RFC 3218-style random key substitution so failed RSA decryptions continue through symmetric decryption and reduce oracle leakage. No active exploitation has been reported, and the vulnerability is not listed in CISA's KEV catalog.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
On August 3, 2026, CVE-2026-69247 was publicly described as a high-severity Bleichenbacher oracle in pyca/cryptography PKCS#7 decryption affecting versions before 50.0.0. The disclosure notes remote exploitability in services such as S/MIME gateways and mail filters that decrypt attacker-supplied EnvelopedData and expose adaptive responses.
On July 31, 2026, pyca/cryptography committed a fix for PKCS#7 RSA PKCS#1 v1.5 encryptedKey handling so decryption failures no longer expose distinguishable errors or timing differences that could enable a Bleichenbacher oracle. The commit also added documentation warning that PKCS#7 EnvelopedData still permits CBC padding oracle risks if applications reveal decryption success.
The pyca/cryptography project fixed CVE-2026-69247 in version 50.0.0. The patch changes PKCS#7 decryption handling to continue with a random fallback key and reduce distinguishable error and timing behavior during RSA PKCS#1 v1.5 processing.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvereports.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.