THREAT OPS › Threat News › [GHSA] GHSA-g6cj-pr64-35w5 (high) — cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
[GHSA] GHSA-g6cj-pr64-35w5 (high) — cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
GHSA-g6cj-pr64-35w5 Severity: high CVE: CVE-2026-69247
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
### Summary
`pkcs7_decrypt_der`, `pkcs7_decrypt_pem`, and `pkcs7_decrypt_smime` reported the outcome of decrypting a `RecipientInfo`'s `encryptedKey` in several distinguishable ways, one of which disclosed the exact length
Indicators of compromise
- CVE-2026-69247cve
Original source: https://github.com/advisories/GHSA-g6cj-pr64-35w5