---
id: CVE-2026-39892
title: >-
  cryptography is a package designed to expose cryptographic primitives and
  recipes to Python developers
summary: >-
  cryptography is a package designed to expose cryptographic primitives and
  recipes to Python developers. From 45.0.0 to before 46.0.7, if a
  non-contiguous buffer was passed to APIs which accepted Python buffers (e.g.
  Hash.update()), this …
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-119
  - CWE-131
vendor: cryptography.io
product: cryptography
affected:
  - 'cryptography >= 45.0.0, < 46.0.7'
patched:
  - cryptography 46.0.7
published: '2026-04-08'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T13:20:00.007'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-39892'
references:
  - url: >-
      https://github.com/pyca/cryptography/security/advisories/GHSA-p423-j2cm-9vmq
    label: security-advisories@github.com
  - url: 'http://www.openwall.com/lists/oss-security/2026/04/08/12'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2026:19375'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:20338'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:21017'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22465'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22629'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22840'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:23361'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:24483'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:24761'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:24762'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:24853'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:24866'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:24977'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:30088'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:30089'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:37275'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:42644'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:43651'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:43670'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:43851'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:43853'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:43854'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:43855'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:46956'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:7295'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-39892'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2456735'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39892.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-39892'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-39892'
  - url: >-
      https://github.com/pyca/cryptography/commit/622d672e429a7cff836a23c5903683dbec1901f5
  - url: 'https://github.com/pyca/cryptography'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2026-36.yaml
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
  - osv
  - pip
  - score-dispute
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-04-09T19:41:57.662246Z'
scores:
  nvd: 9.8
  cna: 6.9
  vendor: 7.3
epss: 0.00652
epssPercentile: 0.49859
ingestedAt: '2026-07-01T15:50:58.769Z'
aliases:
  - GHSA-p423-j2cm-9vmq
  - PYSEC-2026-36
ecosystem: pip
---

## Overview

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.

## Affected

- `cryptography >= 45.0.0, < 46.0.7`

## Remediation

Upgrade past the affected range:

- `cryptography 46.0.7`

## Vendor advisories

- **RHSA-2026:24761** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-06-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:24761)
- **RHSA-2026:24762** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-06-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:24762)
- **RHSA-2026:30089** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-06-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:30089)
- **RHSA-2026:30088** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-06-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:30088)
- **RHSA-2026:24866** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-06-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:24866)
- **RHSA-2026:20338** · Red Hat · fixed in: Red Hat Discovery 2 · released 2026-05-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:20338)
- **RHSA-2026:43855** · Red Hat · fixed in: Red Hat Enterprise Linux AI 3.3 · released 2026-07-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:43855)
- **RHSA-2026:43854** · Red Hat · fixed in: Red Hat Enterprise Linux AI 3.3 · released 2026-07-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:43854)
- **RHSA-2026:43851** · Red Hat · fixed in: Red Hat Enterprise Linux AI 3.3 · released 2026-07-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:43851)
- **RHSA-2026:43670** · Red Hat · fixed in: Red Hat Enterprise Linux AI 3.3 · released 2026-07-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:43670)
- **RHSA-2026:43853** · Red Hat · fixed in: Red Hat Enterprise Linux AI 3.3 · released 2026-07-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:43853)
- **Red Hat VEX** · Important · affected: Lightspeed Core, Migration Toolkit for Applications 8, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform Ansible Core 2, Red Hat Enterprise Linux 8, … · no fix planned: Migration Toolkit for Applications 8, Red Hat AI Inference Server, Red Hat Quay 3, Lightspeed Core, … · updated 2026-09-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39892.json)

## Package advisory (CVE-2026-39892)

Affected packages:

- `cryptography >= 45.0.0, < 46.0.7`

Patched in:

- `cryptography 46.0.7`

Source: https://osv.dev/vulnerability/GHSA-p423-j2cm-9vmq
