A timing side-channel vulnerability has been discovered...
Moderate severity
Unreviewed
Published
Jan 31, 2024
to the GitHub Advisory Database
•
Updated Feb 25, 2026
Description
Published by the National Vulnerability Database
Jan 31, 2024
Published to the GitHub Advisory Database
Jan 31, 2024
Last updated
Feb 25, 2026
A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 padded ciphertexts. This flaw could potentially enable unauthorized RSA ciphertext decryption or signing, even without access to the corresponding private key.
References