Skip to main content

Vendor/product archive

cryptography.io / cryptography CVEs

Beta · best-effort

11 CVEs tagged to cryptography.io / cryptography1 Critical, 5 High, 4 Medium, 1 Low, 0 Unrated.

CVE-2026-39892

Published Apr 8, 2026

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs…

CVSS 6.9 · Medium
evidence mentions
30
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-34073

Published Mar 31, 2026

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against S…

CVSS 1.7 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-26007

Published Feb 10, 2026

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers…

CVSS 8.2 · High
evidence mentions
26
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2024-26130

Published Feb 21, 2024

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serializ…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-49083

Published Nov 29, 2023

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_certificates` or `load_der_pkcs7_certificates` coul…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23931

Published Feb 7, 2023

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1