CVE-2026-44368 - pyquorum: Timing side‑channel in mul_mod

📡 GitHub-Advisory · 2026-05-06

CVE-2026-44368 - pyquorum: Timing side‑channel in mul_mod

CVE-2026-44368

GHSA-7r92-3jgr-r65q MEDIUM pip/pyquorum

CVE: CVE-2026-44368

Impact

The mul_mod function implements multiplication via a binary expansion loop whose execution time depends on the Hamming weight of the second operand (the exponent). An attacker who can measure the time of secret‑sharing operations (e.g., via a remote service) could progressively recover the values of shares, ultimately leading to secret reconstruction.

Patches

https://github.com/svvqt/pyquorum/releases/tag/v0.2.1


📌 来源: GitHub-Advisory | 🆔 CVE-2026-44368 | 📅 2026-05-06

[!] CONTACT_CHANNELS

如需商务合作、技术咨询或漏洞反馈,请通过以下离岸节点联系作者。

> PING_AUTHOR (@A1RedTeam)