{"id":"CVE-2026-69249","title":"python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers","summary":"python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 42.0.0 through 48.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed cert…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-400","CWE-770"],"vendor":"Red Hat","product":"Red Hat Enterprise Linux AppStream (v. 10)","affected":["enterprise_linux 10","enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_9","hardened_images"],"patched":["enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_9","hardened_images"],"published":"2026-08-03","updated":"2026-09-10","sourceUpdated":"2026-09-10T20:36:14.340","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-69249","references":[{"url":"https://github.com/pyca/cryptography/commit/3763aa79b","label":"security-advisories@github.com"},{"url":"https://github.com/pyca/cryptography/commit/4a12cf49675a184e47f912b00b04f3a629283582","label":"security-advisories@github.com"},{"url":"https://github.com/pyca/cryptography/pull/14960","label":"security-advisories@github.com"},{"url":"https://github.com/pyca/cryptography/security/advisories/GHSA-jwv3-5hgf-82ww","label":"security-advisories@github.com"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2026-3553.yaml","label":"security-advisories@github.com"},{"url":"https://github.com/pyca/cryptography/security/advisories/GHSA-jwv3-5hgf-82ww","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-69249.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-69249"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2510815"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-69249"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69249"},{"url":"https://access.redhat.com/errata/RHSA-2026:64795"},{"url":"https://access.redhat.com/errata/RHSA-2026:64774"},{"url":"https://access.redhat.com/errata/RHSA-2026:55543"},{"url":"https://github.com/advisories/GHSA-jwv3-5hgf-82ww"},{"url":"https://github.com/pyca/cryptography"}],"tags":["nvd","csaf","vex","red-hat","ghsa","pip","osv"],"epss":0.00252,"epssPercentile":0.16955,"aliases":["GHSA-jwv3-5hgf-82ww","PYSEC-2026-3553"],"ecosystem":"pip","cvssSource":"vendor","ingestedAt":"2026-08-03T21:30:01.414Z","slug":"CVE-2026-69249","body":"## Overview\n\npython-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 42.0.0 through 48.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candidate, leading to an exponential blowup. Although the limitation that the chain depth cannot exceed a specified maximum depth prevents unbounded recursion and guarantees termination, an attacker-controlled certificate chain can lead the processing to easily take more than 5s to reject in testing. This amplification could form the basis for a resource exhaustion denial of service attack. The core issue arises in the recursive nature of build_chain_inner, which does not de-duplicate against previously analyzed candidates. As the correctness of validation is not affected, the integrity of a system cannot be compromised through this vector, only its availability. This issue is fixed in 49.0.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-69249)\n\nAffected packages:\n\n- `cryptography <= 48.0.0`\n\nPatched in:\n\n- `cryptography 49.0.0`\n\nSource: https://github.com/advisories/GHSA-jwv3-5hgf-82ww\n\n## Vendor advisories\n\n- **RHSA-2026:64795** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:64795)\n- **RHSA-2026:64774** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:64774)\n- **RHSA-2026:55543** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-08-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:55543)\n- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 10 · no fix planned: Red Hat Enterprise Linux 10 · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-69249.json)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":5447,"id":"CVE-2026-69249","ts":1788887282733,"field":"cvss","old":null,"new":"7.5"},{"seq":4330,"id":"CVE-2026-69249","ts":1788886396453,"field":"cvss","old":"7.5","new":null},{"seq":3208,"id":"CVE-2026-69249","ts":1788883133788,"field":"cvss","old":null,"new":"7.5"}]}