CVE-2025-49824 - CVE House
Back to Database
Status published Low CVE-2025-49824

conda-smithy Insecure Encryption Vulnerable to Oracle Padding Attack

Vulnerability Description

conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a single repository. Prior to version 3.47.1, the travis_encrypt_binstar_token implementation in the conda-smithy package has been identified as vulnerable to an Oracle Padding Attack. This vulnerability results from the use of an outdated and insecure padding scheme during RSA encryption. A malicious actor with access to an oracle system can exploit this flaw by iteratively submitting modified ciphertexts and analyzing responses to infer the plaintext without possessing the private key. This issue has been patched in version 3.47.1.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-49824

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

conda-forge

View all reports →

Affected Software

conda-smithy
Vulnerable Versions:
< 3.47.1

Timeline

Official Publish: June 17th, 2025
Last Modified: June 18th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)