python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.
"https://github.com/pypa/advisory-database/blob/main/vulns/cryptography/PYSEC-2021-62.yaml"