← Vulnerability feed

Vulnerability record · CVE-2018-16869 · published 3 December 2018

CVE-2018-16869: Nettle project nettle observable discrepancy vulnerability

Nettle Project · Nettle

A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run a process on the same physical core as the victim process, could use this flaw extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.

5.7 CVSS 3.1 Medium EPSS 1.5% · top 26.7% CWE-203 · Observable discrepancy
5.7CVSS 3.1 base score, v2 3.3
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run a process on the same physical core as the victim process, could use this flaw extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.

CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://cat.eyalro.net/ Technical DescriptionThird Party Advisory
http://www.securityfocus.com/bid/106092 Broken LinkThird Party AdvisoryVDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16869 Issue TrackingThird Party Advisory
http://cat.eyalro.net/ Technical DescriptionThird Party Advisory
http://www.securityfocus.com/bid/106092 Broken LinkThird Party AdvisoryVDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16869 Issue TrackingThird Party Advisory

Track CVE-2018-16869 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-36660Nettle project nettle out-of-bounds write vulnerabilityThe OCB feature in libnettle in Nettle 3.9 before 3.9.1 allows memory corruption.EPSS 1.0%9.8CVE-2015-8805Nettle project nettle vulnerabilityThe ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implement…EPSS 2.8%9.8CVE-2015-8804Nettle project nettle vulnerabilityx86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-…EPSS 3.9%9.8CVE-2015-8803Nettle project nettle vulnerabilityThe ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implement…EPSS 4.2%8.1CVE-2021-20305Nettle project nettle broken cryptographic algorithm vulnerabilityA flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the El…EPSS 1.7%7.5CVE-2021-3580Nettle project nettle improper input validation vulnerabilityA flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a mani…EPSS 2.7%7.5CVE-2016-6489Redhat enterprise linux desktop observable discrepancy vulnerabilityThe RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack.EPSS 5.0%5.3CVE-2024-39891Twilio Authy API phone number enumeration via observable discrepancyAn unauthenticated endpoint in the Twilio Authy API, reachable through Authy Android before 25.1.0 and Authy iOS before 26.1.0, accepted streams of p…KEVEPSS 1.7%analysed

Source: NIST National Vulnerability Database (record CVE-2018-16869), CISA KEV, FIRST EPSS (scores of 2026-10-03). This page is refreshed as NVD updates the record.