VulnSea

cryptography vulnerabilities

CVEs whose affected-version data names the cryptography package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

15 CVEsRSS

GHSA-537c-gmf6-5ccfHigh· 7.5
3mo ago

Vulnerable OpenSSL included in cryptography wheels

Vulnerable OpenSSL included in cryptography wheels

Twilightcryptography · cryptographyvia OSV
CVE-2026-39892Critical· 9.8⚖ disputed
5mo ago

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this …

Midnightcryptography.io · cryptographyEPSS 0.65%via NVD
CVE-2026-34073Medium· 5.3
5mo ago

cryptography has incomplete DNS name constraint enforcement on peer names

cryptography has incomplete DNS name constraint enforcement on peer names

Sunlitcryptography · cryptographyEPSS 0.15%via OSV
CVE-2026-26007Medium· 6.5
7mo ago

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), l…

Sunlitcryptography.io · cryptographyEPSS 0.35%via NVD
CVE-2024-12797Low
1y ago

Vulnerable OpenSSL included in cryptography wheels

Vulnerable OpenSSL included in cryptography wheels

Sunlitcryptography · cryptographyEPSS 2.5%via OSV
GHSA-h4gh-qq45-vh27Medium
2y ago

pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels

pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels

Sunlitcryptography · cryptographyvia OSV
CVE-2024-26130High· 7.5
2y ago

cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private …

cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override

Twilightcryptography · cryptographyEPSS 0.83%via OSV
CVE-2023-50782High· 7.5
2y ago

Python Cryptography package vulnerable to Bleichenbacher timing oracle attack

Python Cryptography package vulnerable to Bleichenbacher timing oracle attack

Twilightcryptography · cryptographyEPSS 1.1%via OSV
CVE-2024-0727Medium· 5.5
2y ago

Null pointer dereference in PKCS12 parsing

Null pointer dereference in PKCS12 parsing

Sunlitcryptography · cryptographyEPSS 3.2%via OSV
CVE-2023-49083Medium· 5.9
2y ago

cryptography vulnerable to NULL-dereference when loading PKCS7 certificates

cryptography vulnerable to NULL-dereference when loading PKCS7 certificates

Sunlitcryptography · cryptographyEPSS 0.98%via OSV
GHSA-v8gr-m533-ghj9Low
3y ago

Vulnerable OpenSSL included in cryptography wheels

Vulnerable OpenSSL included in cryptography wheels

Sunlitcryptography · cryptographyvia OSV
GHSA-jm77-qphf-c4w8Low
3y ago

pyca/cryptography's wheels include vulnerable OpenSSL

pyca/cryptography's wheels include vulnerable OpenSSL

Sunlitcryptography · cryptographyvia OSV
CVE-2023-38325High· 7.5
3y ago

cryptography mishandles SSH certificates

cryptography mishandles SSH certificates

Twilightcryptography · cryptographyEPSS 0.73%via OSV
GHSA-5cpq-8wj7-hf2vLow
3y ago

Vulnerable OpenSSL included in cryptography wheels

Vulnerable OpenSSL included in cryptography wheels

Sunlitcryptography · cryptographyvia OSV
CVE-2023-23931Medium· 6.5
3y ago

Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf

Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf

Sunlitcryptography · cryptographyEPSS 1.3%via OSV
cryptography vulnerabilities (CVEs) · VulnSea