cryptography vulnerabilities
CVEs whose affected-version data names the cryptography package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
15 CVEsRSS
GHSA-537c-gmf6-5ccfHigh· 7.5Vulnerable OpenSSL included in cryptography wheels
Vulnerable OpenSSL included in cryptography wheels
CVE-2026-39892Critical· 9.8⚖ disputedcryptography is a package designed to expose cryptographic primitives and recipes to Python developers
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this …
CVE-2026-34073Medium· 5.3cryptography has incomplete DNS name constraint enforcement on peer names
cryptography has incomplete DNS name constraint enforcement on peer names
CVE-2026-26007Medium· 6.5cryptography is a package designed to expose cryptographic primitives and recipes to Python developers
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), l…
CVE-2024-12797LowVulnerable OpenSSL included in cryptography wheels
Vulnerable OpenSSL included in cryptography wheels
GHSA-h4gh-qq45-vh27Mediumpyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
CVE-2024-26130High· 7.5cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private …
cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override
CVE-2023-50782High· 7.5Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
CVE-2024-0727Medium· 5.5Null pointer dereference in PKCS12 parsing
Null pointer dereference in PKCS12 parsing
CVE-2023-49083Medium· 5.9cryptography vulnerable to NULL-dereference when loading PKCS7 certificates
cryptography vulnerable to NULL-dereference when loading PKCS7 certificates
GHSA-v8gr-m533-ghj9LowVulnerable OpenSSL included in cryptography wheels
Vulnerable OpenSSL included in cryptography wheels
GHSA-jm77-qphf-c4w8Lowpyca/cryptography's wheels include vulnerable OpenSSL
pyca/cryptography's wheels include vulnerable OpenSSL
CVE-2023-38325High· 7.5cryptography mishandles SSH certificates
cryptography mishandles SSH certificates
GHSA-5cpq-8wj7-hf2vLowVulnerable OpenSSL included in cryptography wheels
Vulnerable OpenSSL included in cryptography wheels
CVE-2023-23931Medium· 6.5Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf
Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf