The Python RSA Project maintains a cryptographic library focused on RSA encryption and decryption operations in Python, serving a niche but security-critical role in applications that depend on asymmetric cryptography. Exposure in this vendor's disclosure history has centered on its core RSA implementation; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Python Rsa Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13757HIGH Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security-relevant impact, e.g., by helping an attacker to infer that | Jun 1, 2020 | 7.5 | 25 | NO | NO |
CVE-2020-25658MEDIUM It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted | Nov 12, 2020 | 5.9 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Python Rsa Project.
Media articles that mention a CVE ID that affects a product developed by Python Rsa Project — matched by CVE ID, not by vendor name.