Skip to content

chore(deps): update dependency pycryptodome to v3.19.1 [security]#68

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/pypi-pycryptodome-vulnerability
Open

chore(deps): update dependency pycryptodome to v3.19.1 [security]#68
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/pypi-pycryptodome-vulnerability

Conversation

@renovate
Copy link
Copy Markdown

@renovate renovate Bot commented Apr 27, 2025

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
pycryptodome (source, changelog) ==3.19.0==3.19.1 age adoption passing confidence

PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption

CVE-2023-52323 / GHSA-j225-cvw7-qrx7

More information

Details

PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.

Severity

  • CVSS Score: 7.1 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

Legrandin/pycryptodome (pycryptodome)

v3.19.1: - Zeil

Compare Source

Resolved issues

  • Fixed a side-channel leakage with OAEP decryption that could be
    exploited to carry out a Manger attack. Thanks to Hubert Kario.

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@coveralls
Copy link
Copy Markdown

coveralls commented Apr 27, 2025

Coverage Report for CI Build 26250077915

Coverage remained the same at 27.981%

Details

  • Coverage remained the same as the base build.
  • Patch coverage: No coverable lines changed in this PR.
  • No coverage regressions found.

Uncovered Changes

No uncovered changes found.

Coverage Regressions

No coverage regressions found.


Coverage Stats

Coverage Status
Relevant Lines: 847
Covered Lines: 237
Line Coverage: 27.98%
Coverage Strength: 0.28 hits per line

💛 - Coveralls

@renovate renovate Bot force-pushed the renovate/pypi-pycryptodome-vulnerability branch 2 times, most recently from 8618e65 to 81729b0 Compare April 3, 2026 12:41
@renovate renovate Bot force-pushed the renovate/pypi-pycryptodome-vulnerability branch from 81729b0 to 008734f Compare May 21, 2026 20:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant